Reflected Cross-Site Scripting in Next AI Draw.io by DayuanJiang
CVE-2026-73037
Key Information:
- Vendor
Dayuanjiang
- Status
- Vendor
- CVE Published:
- 13 August 2026
Badges
What is CVE-2026-73037?
Next AI Draw.io versions 0.2.1 through 0.4.16 are susceptible to a reflected cross-site scripting (XSS) flaw stemming from the mcp query parameter not being properly sanitized. This allows attackers to construct malicious URLs that, when accessed, can execute arbitrary JavaScript code in the context of the user's localhost. Such exploitation can lead to unauthorized access to diagram sessions and API data, posing significant security risks to users.
Affected Version(s)
next-ai-draw-io 0.2.1 <= 0.4.16
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
