Server-Side Request Forgery in Refly through Affected Product by Refly
CVE-2026-91199
5.3MEDIUM
What is CVE-2026-91199?
Refly through version 1.1.0 is susceptible to a server-side request forgery (SSRF) vulnerability present in the POST /v1/misc/scrape endpoint. This vulnerability arises due to the lack of validation on caller-supplied URLs, which allows authenticated attackers to manipulate the backend into making requests to potentially sensitive loopback, private, and link-local addresses. Such exploitation could lead to unauthorized access to internal resources, including cloud metadata services, enabling attackers to read critical information such as page titles and descriptions.
Affected Version(s)
refly 0 <= 1.1.0
