PatchSiren

apify CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM apify CVE published 2026-07-16

CVE-2026-46341

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-16T18:16:43.913Z and has not been modified since then. The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.9.21, the fetch-apify-docs tool in src/tools/common/fetch_apify_docs.ts valid [truncated]

LOW apify CVE published 2026-06-10

CVE-2026-46497

Crawlee, a web scraping and browser automation library, is vulnerable to SSRF via sitemap-derived URLs from version 1.0.0 to before version 1.7.0. This issue is patched in version 1.7.0.