Impact
An issue in DayuanJiang next‑ai‑draw‑io version 0.4.13 allows a remote attacker to obtain sensitive information through the x‑ai‑provider component. This vulnerability can lead to the disclosure of confidential data transmitted or stored by the component, exposing users to privacy and security risks. The weakness is identified as CWE‑1390, a data exposure vulnerability caused by inadequate handling of sensitive information.
Affected Systems
The affected software is DayuanJiang next‑ai‑draw‑io 0.4.13. No other vendors or product versions are listed in the CVE record.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating a high severity. The EPSS score is less than 1%, suggesting that exploit attempts are currently rare, and the issue is not listed in the CISA KEV catalog. The likely attack vector is through network-facing requests to the x‑ai‑provider endpoint. While an attacker can gain sensitive information remotely, the low exploitation probability implies that the risk is moderate in the absence of active exploitation campaigns.
OpenCVE Enrichment