# CVE-2026-40608

> Vulnerability · severity: **MEDIUM** (CVSS 6.2).

## Description

Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the embedded HTTP sidecar contains three POST handlers (/api/state, /api/restore, and /api/history-svg) that process incoming requests by accumulating the entire request body into a JavaScript string without any size limitations. Node.js buffers the entire payload in the V8 heap. Sending a sufficiently large body (e.g., 500 MiB or more) will exhaust the process heap memory, leading to an Out-of-Memory (OOM) error that crashes the MCP server. This vulnerability is fixed in 0.4.15.

## Key facts

- **CVE ID:** CVE-2026-40608
- **Published:** 2026-04-21
- **CVSS severity:** MEDIUM
- **CVSS base score:** 6.2
- **CWE codes:** CWE-770

## Affected products

- `dayuanjiang:next_ai_draw.io`

## Primary sources

- NIST NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-40608

## Citation

> AI Analytics. CVE-2026-40608. Retrieved 2026-07-20 from https://api.ai-analytics.org/cve/CVE-2026-40608. Derived from NIST NVD. Licensed CC0.

---

*[Dataset catalog](https://api.ai-analytics.org/datasets/) · [AI Analytics](https://api.ai-analytics.org/) · CC0 1.0*