CVE-2026-50757

7.8

DayuanJiang · next-ai-draw-io

A directory traversal vulnerability in DayuanJiang next-ai-draw-io version 0.4.13 allows local attackers to achieve arbitrary code execution via the mcp-server component.

Executive summary

A directory traversal vulnerability in the DayuanJiang next-ai-draw-io software exposes systems to potential remote code execution via local attack vectors with user interaction.

Vulnerability

This flaw involves a directory traversal weakness in the nex-ai-draw-io/mcp-server component, requiring a local attacker and user interaction, with no initial privileges needed.

Business impact

A successful exploitation of this vulnerability can lead to a total compromise of system confidentiality, integrity, and availability. With a CVSS score of 7.8, this high-severity flaw poses significant operational and security risks, potentially allowing malicious actors to execute arbitrary code and gain complete control over the affected host environment.

Remediation

Immediate Action: Review vendor advisories for DayuanJiang next-ai-draw-io and apply any available patches or updates as soon as they are released.

Proactive Monitoring: Monitor system logs for unusual file access patterns, unexpected process executions, or unauthorized interactions originating from the mcp-server component.

Compensating Controls: Restrict local file system permissions and enforce strict access controls on vulnerable directories to limit the potential impact of traversal attempts.

Exploitation status

Public Exploit Available: No — There is no confirmed public exploit in the available data.

Analyst recommendation

Given the high severity rating and the potential for complete system compromise, IT and security teams must treat this vulnerability with urgency. Administrators should closely monitor the project repository for official patch releases and apply updates immediately upon availability to mitigate the risk of arbitrary code execution.

More DayuanJiang CVEs

Sources