AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T20:17:02.053Z and has not been modified since then. This Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter. Users and administrators should be aware of the potential impact and take necessary actions t [truncated]
A directory traversal vulnerability was reported in next-ai-draw-io version 0.4.13. The vulnerability allows a remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server endpoint. The Common Vulnerabilities and Exposures (CVE) score for this vulnerability is 7.8, with a HIGH severity rating. The CVE record was published on 2026-07-21T20:17:01.947Z and was last modified on 2026-07-22T18:17 [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T20:17:01.843Z and has not been modified since then. The vulnerability affects DayuanJiang next-ai-draw-io 0.4.13, allowing remote attackers to obtain sensitive information via the x-ai-provider component. Users should review and apply patches to prevent sensitive information disclosure.
A remote attacker can obtain sensitive information via the X-Forwarded-For header value in DayuanJiang next-ai-draw-io 0.4.13. The CVE record was published on 2026-07-21T20:17:01.733Z and has not been modified since then. This issue has a critical severity with a CVSS score of 9.8. Users of DayuanJiang next-ai-draw-io 0.4.13 should verify their exposure and apply patches or mitigations as available.