CVE-2026-73037
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Summary
Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and JavaScript. Attackers can craft malicious URLs to execute arbitrary JavaScript in the localhost origin, enabling exfiltration of diagram sessions and API data.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| DayuanJiang | next-ai-draw-io | 0.2.1 <= 0.4.16 | affected |
Weaknesses
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
References
- https://github.com/DayuanJiang/next-ai-draw-io/issues/917
- https://www.vulncheck.com/advisories/next-ai-draw-io-reflected-xss-via-unsanitized-mcp-query-parameter
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.