PatchSiren

DayuanJiang CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH DayuanJiang CVE published 2026-07-21

CVE-2026-50758

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T20:17:02.053Z and has not been modified since then. This Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter. Users and administrators should be aware of the potential impact and take necessary actions t [truncated]

HIGH DayuanJiang CVE published 2026-07-21

CVE-2026-50757

A directory traversal vulnerability was reported in next-ai-draw-io version 0.4.13. The vulnerability allows a remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server endpoint. The Common Vulnerabilities and Exposures (CVE) score for this vulnerability is 7.8, with a HIGH severity rating. The CVE record was published on 2026-07-21T20:17:01.947Z and was last modified on 2026-07-22T18:17 [truncated]

HIGH DayuanJiang CVE published 2026-07-21

CVE-2026-50756

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T20:17:01.843Z and has not been modified since then. The vulnerability affects DayuanJiang next-ai-draw-io 0.4.13, allowing remote attackers to obtain sensitive information via the x-ai-provider component. Users should review and apply patches to prevent sensitive information disclosure.

CRITICAL DayuanJiang CVE published 2026-07-21

CVE-2026-50755

A remote attacker can obtain sensitive information via the X-Forwarded-For header value in DayuanJiang next-ai-draw-io 0.4.13. The CVE record was published on 2026-07-21T20:17:01.733Z and has not been modified since then. This issue has a critical severity with a CVSS score of 9.8. Users of DayuanJiang next-ai-draw-io 0.4.13 should verify their exposure and apply patches or mitigations as available.