MEDIUM
refly-ai
CVE published 2026-09-14
CVE-2026-91199
CVE-2026-91199 is a server-side request forgery vulnerability in Refly through 1.1.0, affecting the POST /v1/misc/scrape endpoint. Authenticated attackers can make the backend issue requests to loopback, private, and link-local addresses, including cloud metadata services, to read page titles and descriptions of internal resources. This vulnerability allows attackers to potentially access internal resourc [truncated]