Impact
The vulnerability is a cross‑site scripting flaw caused by the lack of proper sanitization on the mcp parameter in DayuanJiang next‑ai‑draw‑io 0.4.13. An attacker can submit malicious script code in that parameter, which the application drops into the affected page and executes within the victim’s browser. The execution occurs with the privileges of the user viewing the page, allowing the attacker to run arbitrary client‑side code and potentially compromise user accounts, extract sensitive data, or hijack sessions. This weakness is classified as CWE‑79.
Affected Systems
Only DayuanJiang next‑ai‑draw‑io version 0.4.13 is affected; no other vendors or product versions are listed in the public data.
Risk and Exploitability
The CVSS score of 8.1 marks the issue as high severity, whereas the EPSS score of less than 1% indicates that active exploitation is unlikely at this time. The vulnerability is not included in CISA’s KEV catalog, suggesting it has not yet been widely exploited. The likely attack vector is remote, delivering an HTTP request that contains an unsanitized mcp parameter; no authentication or privileged access is required to trigger the flaw.
OpenCVE Enrichment