---
id: CVE-2026-73037
title: >-
  Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting
  vulnerability in the mcp query parameter that is interpolated without escaping
  into HTML and JavaScript
summary: >-
  Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting
  vulnerability in the mcp query parameter that is interpolated without escaping
  into HTML and JavaScript. Attackers can craft malicious URLs to execute
  arbitra…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-08-13'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:35:08.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73037'
references:
  - url: 'https://github.com/DayuanJiang/next-ai-draw-io/issues/917'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/next-ai-draw-io-reflected-xss-via-unsanitized-mcp-query-parameter
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00155
epssPercentile: 0.05
ingestedAt: '2026-09-09T21:22:45.534Z'
---

## Overview

Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and JavaScript. Attackers can craft malicious URLs to execute arbitrary JavaScript in the localhost origin, enabling exfiltration of diagram sessions and API data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
