PatchSiren

guy-hartstein CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM guy-hartstein CVE published 2026-10-11

CVE-2026-108850

CVE-2026-108850 is a server-side request forgery vulnerability in Company Research Agent through version 2.2.0. The vulnerability allows unauthenticated attackers to trigger outbound requests by injecting unescaped ReportLab paragraph markup into the /generate-pdf endpoint. This vulnerability can be used to leak image responses in returned PDFs and probe reachability. Defenders should assess exposure and [truncated]