CVE-2026-7182
Path Traversal in Diagram
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated pdf. This issue was fixed in version 1.1.1.
| CWE | CWE-22 |
| Vendor | dhtmlx |
| Product | diagram |
| Published | May 15, 2026 |
| Last Updated | May 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for dhtmlx diagram
Be the first to know when new unknown vulnerabilities affecting dhtmlx diagram are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
DHTMLX / Diagram
1.0.0 < 1.1.1
References
Credits
Łukasz Jaworski (Pentest Limited) Tomasz Holeksa (Pentest Limited)