CVE-2026-50755
Deferred Deferred - Pending Action

Information Disclosure in DayuanJiang next-ai-draw-io

Vulnerability report for CVE-2026-50755, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: MITRE

Description

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-22
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
dayuanjiang next-ai-draw-io 0.4.13
dayuanjiang next-ai-draw-io to 0.4.14 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50755 is an authentication bypass vulnerability in the next-ai-draw-io software (version 0.4.13 and earlier). It allows a remote attacker to forge user identities by manipulating the X-Forwarded-For HTTP header. The application incorrectly relies solely on this client-controlled header for user identification without validation, enabling spoofing attacks.

Detection Guidance

To detect this vulnerability, monitor HTTP requests for manipulated X-Forwarded-For headers in next-ai-draw-io version 0.4.13 or earlier. Check logs for requests where the X-Forwarded-For header contains unexpected values or multiple IPs. Use tools like Wireshark or tcpdump to inspect traffic for header manipulation. Verify if user identities are derived solely from this header without additional validation.

Impact Analysis

This vulnerability can lead to severe impacts such as bypassing server-side rate limits, impersonating other users, corrupting telemetry data, and misattributing API costs. Attackers can manipulate the X-Forwarded-For header to forge identities, enabling unlimited requests, privacy violations, and data integrity issues.

Compliance Impact

This vulnerability could violate compliance with GDPR and HIPAA due to unauthorized data access, privacy violations from user impersonation, and integrity issues from telemetry data poisoning. It undermines accountability and audit mechanisms, potentially leading to regulatory penalties.

Mitigation Strategies

Immediately upgrade to a patched version of next-ai-draw-io beyond 0.4.13. Disable reliance on the X-Forwarded-For header for user identification. Implement proper authentication mechanisms and validate user identities through trusted sources. Configure trusted proxy settings if header forwarding is necessary. Monitor for unusual activity or impersonation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50755. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart