Dayuanjiang develops the Next AI Draw.io product, a niche application with a focused vulnerability footprint centered on resource-management weaknesses. The observed signal reflects improper allocation of resources without limits or throttling, a pattern characteristic of applications handling user-supplied workloads. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dayuanjiang over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40608MEDIUM Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the embedded HTTP sidecar contains three POST handlers (/api/st | Apr 21, 2026 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dayuanjiang.
Media articles that mention a CVE ID that affects a product developed by Dayuanjiang — matched by CVE ID, not by vendor name.