Server-Side Request Forgery Vulnerability in MegaParse by The Vibe Company
CVE-2026-85691
8.7HIGH
What is CVE-2026-85691?
MegaParse version 0.0.55 is susceptible to an unauthenticated server-side request forgery (SSRF) vulnerability in the POST /v1/url endpoint. This flaw allows attackers to supply internal URLs or metadata endpoints without requiring authentication, enabling unauthorized access to sensitive information by reading responses directly from the JSON output. Exploiting this vulnerability could compromise the security of internal services and expose critical data.
Affected Version(s)
megaparse 0 <= 0.0.55
