PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-91199 refly-ai CVE debrief

CVE-2026-91199 is a server-side request forgery vulnerability in Refly through 1.1.0, affecting the POST /v1/misc/scrape endpoint. Authenticated attackers can make the backend issue requests to loopback, private, and link-local addresses, including cloud metadata services, to read page titles and descriptions of internal resources. This vulnerability allows attackers to potentially access internal resources without authorization, leading to unauthorized access or reconnaissance. Defenders responsible for Refly deployments, especially those using version 1.1.0 or earlier, should assess exposure and prioritize verification of authentication and authorization controls for the /v1/misc

Vendor
refly-ai
Product
refly
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-14
Original CVE updated
2026-09-23
Advisory published
2026-09-14
Advisory updated
2026-09-23

Who should care

Defenders responsible for Refly deployments, especially those using version 1.1.0 or earlier, should assess exposure and prioritize verification of authentication and authorization controls for the /v1/misc/scrape endpoint.

Why it matters

CVE-2026-91199 is a server-side request forgery vulnerability in Refly through 1.1.0. Authenticated attackers can exploit this vulnerability to make the backend issue requests to internal resources, potentially leading to unauthorized access or reconnaissance. Defenders should prioritize verifying exposure, assessing authentication controls, and monitoring for suspicious requests.

  • Potential unauthorized access to internal resources
  • Possible exposure of cloud metadata services
  • Risk of reconnaissance on internal network resources
  • Need for verification of Refly version and endpoint exposure

Technical summary

The POST /v1/misc/scrape endpoint in Refly through 1.1.0 is vulnerable to server-side request forgery. Authenticated attackers can make the backend issue requests to loopback, private, and link-local addresses, including cloud metadata services, to read page titles and descriptions of internal resources. This vulnerability allows attackers to potentially access internal resources without authorization, leading to unauthorized access or reconnaissance. The vulnerability is confirmed in Refly through version 1.1.0, and defenders should verify exposure, assess authentication controls, and monitor for suspicious requests.

Defensive priority

Defenders should prioritize verifying exposure of the /v1/misc/scrape endpoint, especially in environments with Refly version 1.1.0 or earlier, and assess the feasibility of exploitation.

Recommended defensive actions

  • Verify Refly version and exposure of the /v1/misc/scrape endpoint
  • Assess authentication and authorization controls for the endpoint
  • Monitor for suspicious requests to loopback, private, and link-local addresses
  • Consider implementing compensating controls to restrict access to internal resources
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the scope of affected versions and potential impact on cloud metadata services require further verification and defensive review. The vulnerability is confirmed in Refly through version 1.1.0, and defenders should verify exposure, assess authentication controls, and monitor for suspicious requests. Evidence from the CVE record and NVD entry suggests that the vulnerability can be exploited by authenticated attackers to make the backend issue requests to loop

Sources and references

Verified primary and authoritative sources

  • CVE-2026-91199 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-91199

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-91199 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91199

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.