A high-severity server-side request forgery flaw tracked as CVE-2026-72777 affects Next AI Draw.io through version 0.4.16, allowing unauthenticated remote attackers to access internal HTTP services through the application's POST /api/parse-url endpoint. The issue stems from hostname validation in isPrivateUrl() that relies on string-based checks instead of resolving DNS, enabling attackers to supply hostnames that appear external but resolve to localhost, RFC1918 addresses, or cloud metadata endpoints.
Researchers reported that the endpoint fetches attacker-supplied URLs server-side and returns extracted content, making it possible to exfiltrate responses from internal-only services. The disclosed bypass techniques include DNS rebinding, attacker-controlled DNS, and redirect chains; one proof of concept used a hostname such as 127-0-0-1.sslip.io to read data from a service bound only to 127.0.0.1:9099. The vulnerability carries a CVSS 3.1 score of 8.6, and recommended mitigations include upgrading to a patched release, validating destinations after DNS resolution, blocking redirects into private address space, and restricting server access to internal network resources.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-72777 was published for a high-severity SSRF vulnerability in Next AI Draw.io through version 0.4.16. The entry stated that the POST /api/parse-url endpoint could be exploited remotely by unauthenticated attackers to access internal HTTP services and exfiltrate responses, including cloud metadata.
A GitHub issue disclosed a high-severity SSRF vulnerability in next-ai-draw-io affecting versions up to 0.4.16. The report described how string-only hostname validation in /api/parse-url could be bypassed via DNS rebinding and related techniques, and included a proof of concept showing exfiltration from an internal-only service.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.