PT-2026-71729 · Unknown · Next-Ai-Draw-Io

·

CVE-2026-72777

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Next AI Draw.io versions prior to 0.4.17
Description An issue exists in the 'POST /api/parse-url' endpoint where hostname validation is performed using string patterns without DNS resolution. This allows unauthenticated attackers to use hostnames that bypass these checks but resolve to internal addresses, enabling server-side request forgery (SSRF). This can be used to access arbitrary internal HTTP services and exfiltrate sensitive data, such as cloud metadata.
Recommendations Update Next AI Draw.io to version 0.4.17 or later. As a temporary mitigation, restrict access to the 'POST /api/parse-url' endpoint.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72777

Affected Products

Next-Ai-Draw-Io