Vulnerability CVE-2023-3974


Published: 2023-07-27

Description:
OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.

Type:

CWE-78

(Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') )

 References:
https://github.com/jgraph/drawio/commit/9d6532de36496e77d872d91b1947bb696607d623
https://huntr.dev/bounties/ce75aa04-e4d6-4e0a-9db0-ae84c46ae9e2

Copyright 2026, cxsecurity.com

 

Back to Top