PT-2026-71729 · Unknown · Next-Ai-Draw-Io
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Next AI Draw.io versions prior to 0.4.17
Description
An issue exists in the 'POST /api/parse-url' endpoint where hostname validation is performed using string patterns without DNS resolution. This allows unauthenticated attackers to use hostnames that bypass these checks but resolve to internal addresses, enabling server-side request forgery (SSRF). This can be used to access arbitrary internal HTTP services and exfiltrate sensitive data, such as cloud metadata.
Recommendations
Update Next AI Draw.io to version 0.4.17 or later.
As a temporary mitigation, restrict access to the 'POST /api/parse-url' endpoint.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Next-Ai-Draw-Io