Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio before 18.0.5. Read local files of the web application.
diagrams drawio