Review reviewHigh
CVE-2026-50757
the affected product
Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server
- CVSS
- 7.8
- EPSS
- 0.46% 37.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.22