PatchSiren

dradis CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH dradis CVE published 2026-08-25

CVE-2026-79788

CVE-2026-79788 Dradis Community Edition Server-Side Request Forgery Vulnerability. The Dradis Community Edition has a vulnerability in the ProvidersController and AgentsController, where the authorization check is never applied due to the constant `defined?(Dradis::Pro)` being undefined in CE. This allows any authenticated user to create an AI provider pointing to an arbitrary HTTP/HTTPS address and reass [truncated]