VYPR

Next AI Draw.io

by Dayuanjiang

Source repositories

CVEs (7)

  • CVE-2026-72777HigAug 13, 2026
    risk 0.56cvss 8.6epss 0.00

    Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string…

  • CVE-2026-73037MedAug 13, 2026
    risk 0.40cvss 6.1epss 0.00

    Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and JavaScript. Attackers can craft malicious URLs to execute arbitrary JavaScript in the localhost origin,…

  • CVE-2026-40608MedApr 21, 2026
    risk 0.33cvss 6.2epss 0.00

    Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the embedded HTTP sidecar contains three POST handlers (/api/state, /api/restore, and /api/history-svg) that process incoming requests by accumulating the entire…

  • CVE-2026-50758HigJul 21, 2026
    risk 0.00cvss 8.1epss 0.01

    Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter

  • CVE-2026-50757HigJul 21, 2026
    risk 0.00cvss 7.8epss 0.00

    Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server

  • CVE-2026-50756HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component

  • CVE-2026-50755CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.00

    An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value