Skip to content

Security: jgraph/drawio-desktop

SECURITY.md

Security Policy

Supported Versions

We only accept security reports against the latest release of draw.io Desktop.

Version Supported
Latest ✅
Older ❌

We do not backport fixes to older versions. Please keep your installation up to date.

Reporting a Vulnerability

Please report security vulnerabilities privately through GitHub. Go to the Security tab of this repository and click Report a vulnerability, or use this direct link:

https://github.com/jgraph/drawio-desktop/security/advisories/new

Please do not open a public issue, pull request or discussion for a security vulnerability.

Vulnerabilities in the diagram editor itself, which draw.io Desktop includes from jgraph/drawio, can also be reported there.

To help us triage quickly, include where you can:

  • A description of the vulnerability and its potential impact.
  • The draw.io Desktop version (Help > About) and your operating system.
  • Step-by-step instructions to reproduce it, ideally with a minimal proof of concept.
  • Any relevant logs, screenshots or sample diagram files.

Disclosure Process

  • We will acknowledge your report as soon as we can and keep you updated as we investigate.
  • We ask that you give us a reasonable amount of time to release a fix before any public disclosure.
  • We are happy to credit you in the advisory once the issue is resolved, unless you would prefer to remain anonymous.
Learn more about advisories related to jgraph/drawio-desktop in the GitHub Advisory Database