
🚨Critical - DHTMLX Diagram Export Module Path Traversal (CVE-2026-7182) DHTMLX Diagram's export module is vulnerable to Path Traversal in the src attribute due to insufficient HTML sanitization. An unauthenticated attacker can craft a malicious HTML payload to read arbitrary local files from the server and include their content in the generated PDF. 👉Affected: DHTMLX Diagram < 1.1.1
Post summary
The snippet announces a critical path traversal vulnerability in DHTMLX Diagram's export module that allows unauthenticated local file reads via malicious HTML with the src attribute.
