Server-Side Request Forgery Vulnerability in Company Research Agent
CVE-2026-108850
6.9MEDIUM
What is CVE-2026-108850?
The Company Research Agent before version 2.2.0 is vulnerable to a server-side request forgery (SSRF) attack. This vulnerability allows unauthenticated attackers to leverage unescaped ReportLab paragraph markup to manipulate the /generate-pdf endpoint. By injecting inline img elements into the report_content, attackers can cause the server to make unauthorized outbound requests. These requests can access both internal and external hosts, leading to potential data leakage through image responses rendered in the PDFs, as well as probing for internal network reachability.
Affected Version(s)
company-research-agent 0 <= 2.2.0
