HIGH
dradis
CVE published 2026-08-25
CVE-2026-79788
CVE-2026-79788 Dradis Community Edition Server-Side Request Forgery Vulnerability. The Dradis Community Edition has a vulnerability in the ProvidersController and AgentsController, where the authorization check is never applied due to the constant `defined?(Dradis::Pro)` being undefined in CE. This allows any authenticated user to create an AI provider pointing to an arbitrary HTTP/HTTPS address and reass [truncated]