What is CVE-2026-72777?
This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Next AI Draw.io up to version 0.4.16, affecting the POST /api/parse-url endpoint. The flawed hostname validation only checks string patterns without DNS resolution, allowing unauthenticated attackers to access internal network resources. Users should immediately upgrade to the latest patched version.
Azərbaycanca: Bu CVE Next AI Draw.io-nun 0.4.16 versiyasına qədər olan versiyalarında POST /api/parse-url endpoint-də Server-Side Request Forgery (SSRF) zəifliyini təsvir edir. Hostname doğrulaması yalnız sadə sətir uyğunluğuna əsaslandığı üçün autentifikasiya olunmamış hücumçular xüsusi hazırlanmış hostname-lərlə daxili şəbəkə resurslarına sorğu göndərə bilərlər. İstifadəçilərə bu versiyanı dərhal ən son təhlükəsizlik yeniləməsinə yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Next AI Draw.io are affected by CVE-2026-72777?
This vulnerability affects all versions of Next AI Draw.io up to version 0.4.16.
Is authentication required to exploit the SSRF vulnerability in CVE-2026-72777?
No, this SSRF vulnerability in the POST /api/parse-url endpoint can be exploited by unauthenticated attackers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.