CVE-2026-42195General

LOWCVSS 3.4 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts a ?gitlab= URL parameter that overrides the GitLab server URL used during OAuth sign-in. A crafted link causes the user's click on draw.io's "Authorize in GitLab" dialog to open a popup on the attacker-controlled host instead of gitlab.com. This can lead to credential fishing and session state token exfiltration. This issue has been patched in version 29.7.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • General: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-09); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-27: 1Mentions · 2026-05-09: 2Mentions · 2026-06-22: 104-2705-0906-22
Signal classification1 categories
General
4100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-271
General1
2026-05-092
General2
2026-06-221
General1
Full discourse4 posts
  • flexinz@flexinz_
    General

    Minha primeira CVE, CVE-2026-42195 :) https://t.co/c35YHuJY9M

    Post summary

    The tweet merely announces CVE-2026-42195 with a link, providing no further details or context.

    7306533.2K
    935 followersView on X
  • flexinz@flexinz_
    General

    write-up da minha CVE que eu esqueci de postar aki https://flexinz.com/bug%20bounty/web%20security/draw.io/2026/06/02/cve-2026-42195.html

    Post summary

    The post only shares a link to a write‑up for CVE‑2026‑42195, without presenting any technical or exploitation information.

    110112682
    949 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-42195 http://draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the http://draw.io client accepts a ?gitlab= URL parameter that overrides the G… https://www.cve.org/CVERecord?id=CVE-2026-42195

    Post summary

    The passage provides only a minimal mention of CVE‑2026‑42195 with no concrete details on exploitability, patches, or mitigation.

    0000089
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42195 Open Redirect and Credential Phishing in http://draw.io Prior to Version... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42195 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet simply references CVE-2026-42195 and points to a vulnerability details page without providing substantive information.

    0000082
    4.0K followersView on X

Explore more