CVE-2025-58172 - CVE House
Back to Database
Status published Medium CVE-2025-58172

drawnix debug logging cross-site scripting vulnerability

Vulnerability Description

drawnix is an all in one open-source whiteboard tool. In drawnix versions through 0.2.1, a cross-site scripting (XSS) vulnerability exists in the debug logging functionality. User controlled content is inserted directly into the DOM via innerHTML without sanitization when the global function __drawnix__web__console is invoked, as shown in apps/web/src/app/app.tsx where div.innerHTML = value is executed. This can allow arbitrary JavaScript execution in the context of the application if an attacker can cause untrusted data to be passed to the debug logger (for example via a malicious extension or other injection vector), potentially exposing user data or enabling unauthorized actions. The issue is fixed in version 0.3.0. Updating to 0.3.0 or later is recommended. No known workarounds exist.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-58172

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

plait-board

View all reports →

Affected Software

drawnix
Vulnerable Versions:
< 0.3.0

Timeline

Official Publish: September 15th, 2025
Last Modified: September 15th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)