What is CVE-2026-50755?
A vulnerability in DayuanJiang next-ai-draw-io version 0.4.13 allows a remote attacker to obtain sensitive information through the X-Forwarded-For header value. This can lead to unauthorized disclosure of confidential data from the application. Immediate patching with the vendor's security update is recommended.
Azərbaycanca: DayuanJiang next-ai-draw-io 0.4.13 versiyasında X-Forwarded-For header-i vasitəsilə həssas məlumatların əldə edilməsinə imkan verən zəiflik aşkar edilib. Bu, uzaq təcavüzkarın tətbiqdən məxfi məlumatları oxumasına səbəb ola bilər. Təcili olaraq istehsalçı tərəfindən təqdim ediləcək təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which version of DayuanJiang next-ai-draw-io is affected by CVE-2026-50755?
This vulnerability affects version 0.4.13 of DayuanJiang next-ai-draw-io.
Which HTTP header can an attacker exploit in CVE-2026-50755 to obtain sensitive information?
An attacker can exploit the X-Forwarded-For header to obtain sensitive information.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.