Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-40608: Unbounded request body crashes Next AI Draw.io MCP sidecar

Next AI Draw.io versions prior to 0.4.15 accumulated entire HTTP request bodies into memory in three POST handlers (/api/state, /api/restore, /api/history-svg) of its embedded sidecar, so a large payload (e.g. 500 MiB) could exhaust the Node.js heap and crash the MCP server. The issue is fixed in version 0.4.15.

Disclosed 21 April 2026 · Record updated 13 September 2026

Impact

Out-of-memory denial of service crashing the MCP server hosting the AI diagram integration.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40608