PatchSiren

refly-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM refly-ai CVE published 2026-09-14

CVE-2026-91199

CVE-2026-91199 is a server-side request forgery vulnerability in Refly through 1.1.0, affecting the POST /v1/misc/scrape endpoint. Authenticated attackers can make the backend issue requests to loopback, private, and link-local addresses, including cloud metadata services, to read page titles and descriptions of internal resources. This vulnerability allows attackers to potentially access internal resourc [truncated]