A vulnerability classified as critical has been found in DayuanJiang next-ai-draw-io 0.4.13. Affected by this vulnerability is an unknown functionality of the file /mcp-server of the component mcp-server. Performing a manipulation results in path traversal.
This vulnerability is identified as CVE-2026-50757. The attack can be initiated remotely. There is not any exploit available.