CVE-2026-7182Disclosure

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated pdf. This issue was fixed in version 1.1.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-15: 1Technical Details · 2026-05-15: 105-15
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - DHTMLX Diagram Export Module Path Traversal (CVE-2026-7182) DHTMLX Diagram's export module is vulnerable to Path Traversal in the src attribute due to insufficient HTML sanitization. An unauthenticated attacker can craft a malicious HTML payload to read arbitrary local files from the server and include their content in the generated PDF. 👉Affected: DHTMLX Diagram < 1.1.1

    Post summary

    The snippet announces a critical path traversal vulnerability in DHTMLX Diagram's export module that allows unauthenticated local file reads via malicious HTML with the src attribute.

    0001095
    196 followersView on X

Explore more