← back
CVE-2026-73037mediumCWE-79

Next AI Draw.io 0.2.1 - 0.4.16 Reflected XSS via unsanitized mcp query parameter

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 5.1epss 0.2%
exploitation probability
0.2%top 95% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and JavaScript. Attackers can craft malicious URLs to execute arbitrary JavaScript in the localhost origin, enabling exfiltration of diagram sessions and API data.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.