Description
Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw caused by the lack of proper sanitization on the mcp parameter in DayuanJiang next‑ai‑draw‑io 0.4.13. An attacker can submit malicious script code in that parameter, which the application drops into the affected page and executes within the victim’s browser. The execution occurs with the privileges of the user viewing the page, allowing the attacker to run arbitrary client‑side code and potentially compromise user accounts, extract sensitive data, or hijack sessions. This weakness is classified as CWE‑79.

Affected Systems

Only DayuanJiang next‑ai‑draw‑io version 0.4.13 is affected; no other vendors or product versions are listed in the public data.

Risk and Exploitability

The CVSS score of 8.1 marks the issue as high severity, whereas the EPSS score of less than 1% indicates that active exploitation is unlikely at this time. The vulnerability is not included in CISA’s KEV catalog, suggesting it has not yet been widely exploited. The likely attack vector is remote, delivering an HTTP request that contains an unsanitized mcp parameter; no authentication or privileged access is required to trigger the flaw.

Generated by OpenCVE AI on August 4, 2026 at 05:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade next‑ai‑draw‑io to a release that includes the XSS fix.
  • Contain the application by limiting inbound traffic through firewall rules or network segmentation to restrict exposure to the vulnerable endpoint.
  • Deploy input validation or a web application firewall to reject or properly encode untrusted data supplied via the mcp parameter.

Generated by OpenCVE AI on August 4, 2026 at 05:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via Unsanitized mcp Parameter in DayuanJiang next‑ai‑draw‑io 0.4.13

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via Unsanitized mcp Parameter in DayuanJiang next‑ai‑draw‑io 0.4.13

Wed, 29 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Allowing Remote Code Execution via mcp Parameter in DayuanJiang next‑ai‑draw‑io 0.4.13

Fri, 24 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Allowing Remote Code Execution via mcp Parameter in DayuanJiang next‑ai‑draw‑io 0.4.13

Thu, 23 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Dayuanjiang
Dayuanjiang next-ai-draw-io
Vendors & Products Dayuanjiang
Dayuanjiang next-ai-draw-io

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter
References

Subscriptions

Dayuanjiang Next-ai-draw-io
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-22T17:52:05.589Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50758

cve-icon Vulnrichment

Updated: 2026-07-22T17:50:29.906Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T06:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')