{"api_version":"v1","generated_at":"2026-10-08T00:30:00+00:00","product":{"cve_count":7,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-jgraph-drawio-4c6d980501f3","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/drawio","name":"drawio","next_cursor":null,"observations":[{"affected":"drawio: < 30.3.8","affected_versions_present":true,"cve_id":"CVE-2026-76898","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-76898","fixed":"30.3.8.","last_modified":"2026-09-24T22:21:52.041Z","patch_url":"https://github.com/jgraph/drawio/security/advisories/GHSA-m3q9-cwfq-hcjc","primary_source":"","published":"2026-09-21T16:31:54.813Z"},{"affected":"drawio: < 30.2.7","affected_versions_present":true,"cve_id":"CVE-2026-63373","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63373","fixed":"30.2.7.","last_modified":"2026-09-21T18:02:18.542Z","patch_url":"https://github.com/jgraph/drawio/security/advisories/GHSA-mcj5-3pww-7g49","primary_source":"","published":"2026-09-21T16:29:43.768Z"},{"affected":"drawio: < 30.2.7","affected_versions_present":true,"cve_id":"CVE-2026-63334","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63334","fixed":"30.2.7.","last_modified":"2026-09-21T18:56:03.135Z","patch_url":"https://github.com/jgraph/drawio/security/advisories/GHSA-3v4h-8r2c-m8c5","primary_source":"","published":"2026-09-21T16:22:59.708Z"},{"affected":"drawio: < 30.2.7","affected_versions_present":true,"cve_id":"CVE-2026-63416","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63416","fixed":"30.2.7.","last_modified":"2026-09-24T22:19:57.647Z","patch_url":"https://github.com/jgraph/drawio/security/advisories/GHSA-3pq9-9hg4-ggfw","primary_source":"","published":"2026-09-21T16:18:39.198Z"},{"affected":"drawio: < 30.2.5","affected_versions_present":true,"cve_id":"CVE-2026-58504","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-58504","fixed":"30.2.5.","last_modified":"2026-09-29T15:05:34.205Z","patch_url":"https://github.com/jgraph/drawio/security/advisories/GHSA-c76x-r78m-phwx","primary_source":"","published":"2026-09-21T16:15:30.398Z"},{"affected":"< 29.7.12","affected_versions_present":true,"cve_id":"CVE-2026-46642","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46642","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-11T14:03:34.537Z","patch_url":"https://github.com/jgraph/drawio/security/advisories/GHSA-fqhg-287p-c6vf","primary_source":"","published":"2026-06-10T17:42:02.156Z"},{"affected":"< 29.7.9","affected_versions_present":true,"cve_id":"CVE-2026-42195","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42195","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-13T17:47:31.482Z","patch_url":"","primary_source":"","published":"2026-05-08T21:22:40.678Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"jgraph"}}
