
CVE-2026-73037 Reflected XSS in Next AI https://Draw.io 0.2.1-0.4.16 via mcp Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73037
Post summary
The post reports a reflected XSS vulnerability in Next AI (Draw.io) versions 0.2.1‑0.4.16 caused by the mcp parameter, but supplies no PoC, exploit, patch, or evidence of active exploitation.
