CVE-2026-50756
7.5DayuanJiang · next-ai-draw-io
A sensitive information disclosure vulnerability in the x-ai-provider component of DayuanJiang next-ai-draw-io 0.4.13 allows remote unauthenticated attackers to obtain confidential data.
Executive summary
An information disclosure vulnerability in DayuanJiang next-ai-draw-io version 0.4.13 allows unauthenticated remote attackers to harvest sensitive data.
Vulnerability
This information disclosure flaw resides within the x-ai-provider component, allowing unauthenticated remote attackers with network access to retrieve sensitive data without requiring user interaction.
Business impact
A successful exploit could expose confidential organizational or user data, leading to severe privacy violations, intellectual property theft, or secondary attacks using leaked credentials. With a CVSS score of 7.5, this high severity rating reflects the trivial remote attack vector and the direct impact on data confidentiality.
Remediation
Immediate Action: Review the official GitHub repository for DayuanJiang next-ai-draw-io to check for available patches or apply mitigating configurations to the x-ai-provider component.
Proactive Monitoring: Monitor network traffic and application logs for abnormal data exfiltration patterns or unauthorized requests directed at the x-ai-provider component.
Compensating Controls: Implement a Web Application Firewall rule to block suspicious query structures targeting the vulnerable component if an official update is not immediately available.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept reference exists via the linked researcher GitHub advisory.
Analyst recommendation
Security teams must prioritize monitoring this repository for vendor patches and restrict network access to the affected next-ai-draw-io instance. Applying updates immediately upon release is critical to preventing unauthorized information disclosure.