Description
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in DayuanJiang next‑ai‑draw‑io version 0.4.13 allows a remote attacker to obtain sensitive information through the x‑ai‑provider component. This vulnerability can lead to the disclosure of confidential data transmitted or stored by the component, exposing users to privacy and security risks. The weakness is identified as CWE‑1390, a data exposure vulnerability caused by inadequate handling of sensitive information.

Affected Systems

The affected software is DayuanJiang next‑ai‑draw‑io 0.4.13. No other vendors or product versions are listed in the CVE record.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating a high severity. The EPSS score is less than 1%, suggesting that exploit attempts are currently rare, and the issue is not listed in the CISA KEV catalog. The likely attack vector is through network-facing requests to the x‑ai‑provider endpoint. While an attacker can gain sensitive information remotely, the low exploitation probability implies that the risk is moderate in the absence of active exploitation campaigns.

Generated by OpenCVE AI on August 4, 2026 at 05:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Limit external traffic to the x‑ai‑provider endpoint by configuring firewall rules or network segmentation to reduce the component’s reachability from outside the trust boundary.
  • Monitor application and network logs for unusual requests to the x‑ai‑provider to detect potential exploitation and investigate promptly.
  • Plan to upgrade to a newer version of DayuanJiang next‑ai‑draw‑io once the vendor releases a patch that addresses the information disclosure issue.

Generated by OpenCVE AI on August 4, 2026 at 05:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Information Disclosure via x‑ai‑provider in next‑ai‑draw‑io 0.4.13

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure via x‑ai‑provider in next‑ai‑draw‑io 0.4.13

Wed, 29 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure in next‑ai‑draw‑io via x‑ai‑provider Component

Fri, 24 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure in next‑ai‑draw‑io via x‑ai‑provider Component

Thu, 23 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Dayuanjiang
Dayuanjiang next-ai-draw-io
Vendors & Products Dayuanjiang
Dayuanjiang next-ai-draw-io

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1390
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component
References

Subscriptions

Dayuanjiang Next-ai-draw-io
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-22T17:57:13.872Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50756

cve-icon Vulnrichment

Updated: 2026-07-22T17:56:52.210Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T06:00:05Z

Weaknesses