MEDIUM
guy-hartstein
CVE published 2026-10-11
CVE-2026-108850
CVE-2026-108850 is a server-side request forgery vulnerability in Company Research Agent through version 2.2.0. The vulnerability allows unauthenticated attackers to trigger outbound requests by injecting unescaped ReportLab paragraph markup into the /generate-pdf endpoint. This vulnerability can be used to leak image responses in returned PDFs and probe reachability. Defenders should assess exposure and [truncated]