Server-Side Request Forgery in Huly Platform Print Service
CVE-2026-91079
6.3MEDIUM
What is CVE-2026-91079?
The Huly Platform through version 0.7.426 is susceptible to a server-side request forgery (SSRF) vulnerability within its print service. This issue arises from the absence of hostname allowlist validation, allowing authenticated users to submit arbitrary URLs to the print endpoint. This functionality is exploited by Puppeteer to render these URLs, resulting in downloadable PDFs or images. Consequently, this flaw can grant unauthorized access to sensitive internal metadata services and network hosts, potentially leading to further exploitation within the internal network.
Affected Version(s)
platform 0 <= 0.7.426
