CVE-2026-50756 Details
Description
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component
A Server-Side Request Forgery (SSRF) vulnerability has been identified in DayuanJiang next-ai-draw-io version 0.4.13. This vulnerability allows remote attackers to bypass the application's SSRF guard and redirect server-side AI API calls to attacker-controlled endpoints. The exploitation involves manipulating the 'x-ai-provider' and 'x-ai-base-url' headers, leading to the unauthorized disclosure of sensitive information such as the full AI system prompt, user conversation data, and the current diagram XML content.
To address this vulnerability, remove the provider-based exemptions from the SSRF guard, apply the guard uniformly to all providers, or validate the 'x-ai-provider' header against the server's actual configuration.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 21, 2026CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/August829/Yu/blob/main/CVE-2026-50756.md | [email protected] | Technical Description |
| https://github.com/DayuanJiang/next-ai-draw-io/issues/749 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1390 | Weak Authentication | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| DayuanJiang next-ai-draw-io | <= 0.4.13 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | [email protected] |
Volerion