VulnAI


EUVD-2026-30539

ID: EUVD-2026-30539

Severity: critical

CVSS v4: 9.2 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N)

CVSS v3: Not provided

CWE: None listed

Source: ENISA

Description

Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated pdf. This issue was fixed in version 1.1.1.

Timestamps

References

No references provided.