Vendor
Next AI Draw.io versions 0.4.16 and earlier are vulnerable to unauthenticated SSRF via the /api/parse-url endpoint due to incomplete hostname validation.