Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-50755: DayuanJiang next-ai-draw-io Exposes Sensitive Information
CVE-2026-50755
CVE-2026-50755
Summary
A vulnerability in DayuanJiang next-ai-draw-io version 0.4.13 allows a hacker to access sensitive information from the internet. This could happen if the attacker is able to manipulate the X-Forwarded-For header value. To fix this, update to the latest version of the software.
Original title
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value
Original description
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value
Vulnerability type
CWE-290
Published: 21 Jul 2026 · Updated: 23 Jul 2026 · First seen: 21 Jul 2026