CVE-2026-50756

7.5

DayuanJiang · next-ai-draw-io

A sensitive information disclosure vulnerability in the x-ai-provider component of DayuanJiang next-ai-draw-io 0.4.13 allows remote unauthenticated attackers to obtain confidential data.

Executive summary

An information disclosure vulnerability in DayuanJiang next-ai-draw-io version 0.4.13 allows unauthenticated remote attackers to harvest sensitive data.

Vulnerability

This information disclosure flaw resides within the x-ai-provider component, allowing unauthenticated remote attackers with network access to retrieve sensitive data without requiring user interaction.

Business impact

A successful exploit could expose confidential organizational or user data, leading to severe privacy violations, intellectual property theft, or secondary attacks using leaked credentials. With a CVSS score of 7.5, this high severity rating reflects the trivial remote attack vector and the direct impact on data confidentiality.

Remediation

Immediate Action: Review the official GitHub repository for DayuanJiang next-ai-draw-io to check for available patches or apply mitigating configurations to the x-ai-provider component.

Proactive Monitoring: Monitor network traffic and application logs for abnormal data exfiltration patterns or unauthorized requests directed at the x-ai-provider component.

Compensating Controls: Implement a Web Application Firewall rule to block suspicious query structures targeting the vulnerable component if an official update is not immediately available.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept reference exists via the linked researcher GitHub advisory.

Analyst recommendation

Security teams must prioritize monitoring this repository for vendor patches and restrict network access to the affected next-ai-draw-io instance. Applying updates immediately upon release is critical to preventing unauthorized information disclosure.

More DayuanJiang CVEs

Sources