What is CVE-2026-73037?
This CVE is a reflected XSS vulnerability in the Next AI Draw.io plugin, exploitable via unsanitized 'mcp' query parameter, allowing arbitrary JavaScript execution in localhost origin to exfiltrate data. Users should immediately update to a patched version.
Azərbaycanca: Bu CVE Next AI Draw.io plagini üçün əks olunan XSS zəifliyidir, mcp sorğu parametri vasitəsilə işləyir. İstifadədə olan versiyaları dərhal yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What is CVE-2026-73037?
It is a reflected XSS vulnerability in the Next AI Draw.io plugin, exploitable via the unsanitized 'mcp' query parameter.
What action should be taken regarding CVE-2026-73037?
Users should immediately update to a patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.