Description
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can extract sensitive data by exploiting how the application processes the X-Forwarded-For HTTP header, causing confidential information to be unintentionally exposed. The flaw is an information‑disclosure weakness, specifically CWE-290. The impact is that an unauthenticated remote user may obtain data that should be protected.

Affected Systems

DayuanJiang next-ai-draw-io, version 0.4.13, is affected. No other products or versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not catalogued in CISA KEV. The likely attack vector is a remote request targeting the web interface, injecting a crafted X-Forwarded-For header to retrieve sensitive information.

Generated by OpenCVE AI on August 4, 2026 at 17:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade next-ai-draw-io to the latest release that contains the fix for CVE-2026-50755.
  • If upgrading immediately is not possible, disable or remove the use of the X-Forwarded-For header in the request handling before passing data to the application.
  • Implement web-application firewall rules to validate or strip the X-Forwarded-For header from incoming requests to prevent accidental leakage.

Generated by OpenCVE AI on August 4, 2026 at 17:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Sensitive Information Disclosure via X-Forwarded-For Header in next-ai-draw-io

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Sensitive Information Disclosure via X-Forwarded-For Header in next-ai-draw-io

Wed, 29 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Sensitive Information Disclosure via X-Forwarded-For Header in next-ai-draw-io

Fri, 24 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Sensitive Information Disclosure via X-Forwarded-For Header in next-ai-draw-io

Thu, 23 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Dayuanjiang
Dayuanjiang next-ai-draw-io
Vendors & Products Dayuanjiang
Dayuanjiang next-ai-draw-io

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value
References

Subscriptions

Dayuanjiang Next-ai-draw-io
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-22T17:58:49.988Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50755

cve-icon Vulnrichment

Updated: 2026-07-22T17:58:24.024Z

cve-icon NVD

Status : Deferred

Published: 2026-07-21T20:17:01.733

Modified: 2026-07-22T18:17:00.540

Link: CVE-2026-50755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing