
Cloud Vulnerability DB
A community-led vulnerabilities database
A Cross-Site Scripting (XSS) vulnerability was identified in diagram-js, affecting versions prior to 3.3.1 (for 3.x) and 2.6.2 (for 2.x). The vulnerability was discovered in the search-pad component where user input was not properly escaped, potentially allowing attackers to execute arbitrary JavaScript in the context of websites embedding the affected modelers (GitHub Advisory).
The vulnerability stems from the search-pad component's failure to properly escape user-controlled input. The issue specifically affected the HTML text creation functionality where matched and normal text tokens were being directly inserted into the HTML without proper escaping. This was fixed by implementing the escapeHTML function to sanitize the user input before rendering (Diagram JS Commit).
The vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of a website embedding the affected modelers if a victim was lured into pasting crafted HTML content. The issue affected all editors for BPMN, CMMN, and DMN, though viewer distributions were not impacted (BPMN Blog).
The vulnerability could be exploited by convincing a user to paste specially crafted HTML content into the affected components. The search functionality and direct editing features were the primary attack vectors (BPMN Blog).
Users are recommended to upgrade to the patched versions: diagram-js version 3.3.1 for 3.x users or version 2.6.2 for 2.x users. The fix involves proper HTML escaping of user input in the search-pad component (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."