CVE-2026-50758

8.1

DayuanJiang · next-ai-draw-io

A cross-site scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows remote attackers to execute arbitrary code via the mcp parameter.

Executive summary

A high-severity cross-site scripting vulnerability in the DayuanJiang next-ai-draw-io software allows remote attackers to execute arbitrary code.

Vulnerability

This cross-site scripting flaw involves improper neutralization of input supplied via the mcp parameter, requiring user interaction and no prior privileges from a network attacker.

Business impact

A successful exploit can lead to unauthorized access, sensitive data compromise, and integrity loss within the affected application. Given the high CVSS score of 8.1, organizations face substantial risk of operational disruption and potential data theft if malicious payloads are successfully delivered to users.

Remediation

Immediate Action: Review vendor advisory details on GitHub and apply any available updates or restrict access to vulnerable endpoints.

Proactive Monitoring: Monitor web server access logs for anomalous requests targeting the mcp parameter in the application.

Compensating Controls: Implement a web application firewall rule to filter and sanitize input destined for the vulnerable mcp parameter.

Exploitation status

Public Exploit Available: Yes, reference links include published proof-of-concept material on GitHub repositories.

Analyst recommendation

Security teams must treat this high-severity vulnerability with urgency by closely monitoring vendor communications for an official patch. Administrators should apply compensating controls immediately to mitigate potential exploitation risks until a permanent update is released.

More DayuanJiang CVEs

Sources