A vulnerability was found in DayuanJiang next-ai-draw-io up to 0.4.16. It has been classified as problematic. Affected is an unknown function. Performing a manipulation of the argument mcp results in cross site scripting.
This vulnerability is identified as CVE-2026-73037. The attack can be initiated remotely. There is not any exploit available.