Description
Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address. Authenticated attackers can make the backend issue requests to loopback, private, and link-local addresses including cloud metadata services to read page titles and descriptions of internal resources.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery exposing internal resources and metadata
Action: Patch Now
AI Analysis

Impact

Refly through 1.1.0 contains a server‑side request forgery vulnerability in the POST /v1/misc/scrape endpoint. The endpoint accepts a caller‑supplied URL and retrieves the referenced page without validating the scheme, host, or resolved address. Because the request is made by the backend, an authenticated attacker can instruct it to access internal or private networks, including loopback, link‑local, and private IP ranges, as well as cloud metadata services. The attacker can read the page title and description returned by those internal resources, potentially exposing internal URLs, application endpoints, or secrets returned by metadata services.

Affected Systems

The vulnerability affects the refly‑ai:refly product, specifically1/misc/scrape API path is deployed.

Risk and Exploitability

The CVSS score of 5.3 characterizes the vulnerability as moderate. An EPSS score of <1% indicates a low probability of exploitation in the current window. It is not listed in the CISA KEV catalog. Attackers must authenticate to the API; after authentication they can submit a malicious URL. The backend then performs an HTTP request to the target., it can reach internal resources, loopback addresses, and cloud metadata services, thereby exposing internal URLs and potentially sensitive configuration information. In environments where the server can reach private networks, the risk rises.

Generated by OpenCVE AI on September 17, 2026 at 18:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor patch or update that addresses SSRF in the /v1/misc/scrape endpoint.
  • If a patch is unavailable, restrict the endpoint so that only privileged users can invoke it and implement strict input validation that rejects URLs pointing to localhost, 127.0.0.1, any private IP ranges, and disallows protocols such as file:// or ftp://.
  • Configure the API server or network infrastructure to prevent the /v1/misc/scrape route from accessing private, loopback,

Generated by OpenCVE AI on September 17, 2026 at 18:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address. Authenticated attackers can make the backend issue requests to loopback, private, and link-local addresses including cloud metadata services to read page titles and descriptions of internal resources.
Title Refly through 1.1.0 Server-Side Request Forgery via scrape endpoint
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:16.169Z

Reserved: 2026-09-14T21:55:43.349Z

Link: CVE-2026-91199

cve-icon Vulnrichment

Updated: 2026-09-17T18:29:12.767Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T23:19:00.473

Modified: 2026-09-23T17:17:44.767

Link: CVE-2026-91199

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)