Server-Side Request Forgery in Next AI Draw.io by DayuanJiang
CVE-2026-72777
Key Information:
- Vendor
Dayuanjiang
- Status
- Vendor
- CVE Published:
- 13 August 2026
Badges
What is CVE-2026-72777?
Next AI Draw.io prior to version 0.4.16 is susceptible to a server-side request forgery vulnerability within its POST /api/parse-url endpoint. The flaw arises from insufficient hostname validation, which relies on pattern matching instead of DNS resolution. This vulnerability allows unauthenticated attackers to manipulate hostnames that may bypass standard string validation checks, granting access to internal HTTP services. Consequently, attackers can exfiltrate sensitive information, including cloud metadata, by interfacing with internal network resources.
Affected Version(s)
next-ai-draw-io 0 <= 0.4.16
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
