Impact
An attacker can extract sensitive data by exploiting how the application processes the X-Forwarded-For HTTP header, causing confidential information to be unintentionally exposed. The flaw is an information‑disclosure weakness, specifically CWE-290. The impact is that an unauthenticated remote user may obtain data that should be protected.
Affected Systems
DayuanJiang next-ai-draw-io, version 0.4.13, is affected. No other products or versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not catalogued in CISA KEV. The likely attack vector is a remote request targeting the web interface, injecting a crafted X-Forwarded-For header to retrieve sensitive information.
OpenCVE Enrichment