HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-72777 — Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerabil...

·Source: NIST NVD

Updated:

Executive Summary

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses, allowing them to reach arbitrary internal HTTP services and exfiltrate responses inc

Analysis

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses, allowing them to reach arbitrary internal HTTP services and exfiltrate responses including cloud metadata. CVSS Score: 8.6. Published: 2026-08-13T19:17:32.320.

Indicators of Compromise (2)

CVE (1)
CVE-2026-72777
Domain (1)
Source Attribution

Originally published by NIST NVD on Aug 13, 2026. Verified by: NIST.

Related Threats