A vulnerability, which was classified as problematic, was found in DayuanJiang next-ai-draw-io 0.4.13. This vulnerability affects unknown code of the component MCP. The manipulation of the argument mcp results in cross site scripting.

This vulnerability is cataloged as CVE-2026-50758. The attack may be launched remotely. There is no exploit available.