
Minha primeira CVE, CVE-2026-42195 :) https://t.co/c35YHuJY9M
Post summary
The tweet merely announces CVE-2026-42195 with a link, providing no further details or context.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts a ?gitlab= URL parameter that overrides the GitLab server URL used during OAuth sign-in. A crafted link causes the user's click on draw.io's "Authorize in GitLab" dialog to open a popup on the attacker-controlled host instead of gitlab.com. This can lead to credential fishing and session state token exfiltration. This issue has been patched in version 29.7.9.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE
| Date | Total | Labels |
|---|
| 2026-04-27 | 1 | General1 |
| 2026-05-09 | 2 | General2 |
| 2026-06-22 | 1 | General1 |

Minha primeira CVE, CVE-2026-42195 :) https://t.co/c35YHuJY9M
Post summary
The tweet merely announces CVE-2026-42195 with a link, providing no further details or context.

write-up da minha CVE que eu esqueci de postar aki https://flexinz.com/bug%20bounty/web%20security/draw.io/2026/06/02/cve-2026-42195.html
Post summary
The post only shares a link to a write‑up for CVE‑2026‑42195, without presenting any technical or exploitation information.

CVE-2026-42195 http://draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the http://draw.io client accepts a ?gitlab= URL parameter that overrides the G… https://www.cve.org/CVERecord?id=CVE-2026-42195
Post summary
The passage provides only a minimal mention of CVE‑2026‑42195 with no concrete details on exploitability, patches, or mitigation.

CVE-2026-42195 Open Redirect and Credential Phishing in http://draw.io Prior to Version... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42195 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1
Post summary
The tweet simply references CVE-2026-42195 and points to a vulnerability details page without providing substantive information.