Next AI Draw.io 0.4.16 SSRF via DNS Rebinding in parse-url
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.7epss 0.3%
exploitation probability
0.3%top 75% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses, allowing them to reach arbitrary internal HTTP services and exfiltrate responses including cloud metadata.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Affected products
DayuanJiang · next-ai-draw-iopublic PoCs found — 1
cve_referencegithub.com/DayuanJiang/next-ai-draw-io/issues/918unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.