What is CVE-2026-50757?
This vulnerability is a Directory Traversal issue found in DayuanJiang next-ai-draw-io version 0.4.13. A remote attacker can execute arbitrary code via the /mcp-server path. It is recommended to immediately update the application to the latest version to mitigate this issue.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which version of DayuanJiang next-ai-draw-io is affected by CVE-2026-50757?
The vulnerability was specifically discovered in version 0.4.13.
How is arbitrary code execution achieved when exploiting CVE-2026-50757?
A remote attacker can execute arbitrary code by exploiting the Directory Traversal vulnerability via the /mcp-server path.
See also6
grounded ✓NVD ↗
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.