SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.
{
"cna_assigner": "@huntrdev",
"cwe_ids": [
"CWE-918"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1713.json"
}{
"cpe": "cpe:2.3:a:diagrams:drawio:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "18.0.4"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1713.json"
"2026-07-22T02:23:36Z"
[
{
"signature_version": "v1",
"source": "https://github.com/jgraph/drawio/commit/283d41ec80ad410d68634245cf56114bc19331ee",
"id": "CVE-2022-1713-3d348485",
"digest": {
"threshold": 0.9,
"line_hashes": [
"256138604713525548233859977297912413006",
"15285394560703113076303584509544579630",
"284902276514042524034392390730601888618",
"184903095291267446894621223903129841529",
"204051254849844499799742186179198515434",
"277338863936581628899070227189583858088",
"281400866797574499581982743818650408487",
"117706299045054261825197580809466061163",
"293240033179754798767399788495950561334",
"306756604186503922713611466769509874665",
"10239423091478589037538090427107818842",
"93801423158727263929705122537487999359",
"116982537745088723915661659426382872950",
"227928915469785289738923511538946089511",
"55817800164619556456300909066097764725",
"298725413207184222365098711954728414117",
"232562020996020581991246134075717247053",
"296698945148292485364198943527740401662",
"131473823411446261381411758138038561696",
"308581824498739115004734733275908129743",
"244373857958628979457839806730934705171",
"28986121857531748243717167447975578859",
"158277917938090931111819373957853904463",
"328509342953763162015191303956304634238",
"53655598395850380565981614176161247172",
"301228312995853323581055163718483935039",
"283975385530663619641018001730630815498",
"225182821735074255616215493275788726321",
"31646765161449825127780945202555053882",
"108129965786006130275100108708532602208",
"98906982163799432555904320447908339419",
"106773198214546888673902504438109980390",
"285078168829354315583439896010497075152",
"319262460004466395576581193683125806021",
"238009981099151212674827039683586444388",
"101137531862762476912576195260096406002",
"239436057119325947728146148018967655899",
"189537775409323468863744292565699794737",
"116136237777338686928879407449425903630",
"319892909989994938184130715676254879520",
"70688350822016584305501734175344091000",
"333074141710635353878506192750459148821"
]
},
"target": {
"file": "src/main/java/com/mxgraph/online/ProxyServlet.java"
},
"deprecated": false,
"signature_type": "Line"
},
{
"signature_version": "v1",
"source": "https://github.com/jgraph/drawio/commit/283d41ec80ad410d68634245cf56114bc19331ee",
"id": "CVE-2022-1713-e238248f",
"digest": {
"length": 1272.0,
"function_hash": "13221772121307702109720013784892878136"
},
"target": {
"function": "checkUrlParameter",
"file": "src/main/java/com/mxgraph/online/ProxyServlet.java"
},
"deprecated": false,
"signature_type": "Function"
}
]