We only accept security reports against the latest release of draw.io Desktop.
| Version | Supported |
|---|---|
| Latest | ✅ |
| Older | ❌ |
We do not backport fixes to older versions. Please keep your installation up to date.
Please report security vulnerabilities privately through GitHub. Go to the Security tab of this repository and click Report a vulnerability, or use this direct link:
https://github.com/jgraph/drawio-desktop/security/advisories/new
Please do not open a public issue, pull request or discussion for a security vulnerability.
Vulnerabilities in the diagram editor itself, which draw.io Desktop includes from jgraph/drawio, can also be reported there.
To help us triage quickly, include where you can:
- A description of the vulnerability and its potential impact.
- The draw.io Desktop version (Help > About) and your operating system.
- Step-by-step instructions to reproduce it, ideally with a minimal proof of concept.
- Any relevant logs, screenshots or sample diagram files.
- We will acknowledge your report as soon as we can and keep you updated as we investigate.
- We ask that you give us a reasonable amount of time to release a fix before any public disclosure.
- We are happy to credit you in the advisory once the issue is resolved, unless you would prefer to remain anonymous.