SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-50755

CRITICAL · CVSS 9.8 EPSS 0.43% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A vulnerability in DayuanJiang next-ai-draw-io version 0.4.13 allows remote attackers to exploit the X-Forwarded-For header, potentially leading to the exposure of sensitive information. Organizations using this version should prioritize remediation efforts due to the critical severity rating, as it poses a significant risk of data leakage. Immediate action is recommended for those managing applications that utilize this software.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-50755
Severity
CRITICAL
CVSS
9.8
EPSS
0.43%

Original NVD Description

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value