Impact
Refly through 1.1.0 contains a server‑side request forgery vulnerability in the POST /v1/misc/scrape endpoint. The endpoint accepts a caller‑supplied URL and retrieves the referenced page without validating the scheme, host, or resolved address. Because the request is made by the backend, an authenticated attacker can instruct it to access internal or private networks, including loopback, link‑local, and private IP ranges, as well as cloud metadata services. The attacker can read the page title and description returned by those internal resources, potentially exposing internal URLs, application endpoints, or secrets returned by metadata services.
Affected Systems
The vulnerability affects the refly‑ai:refly product, specifically1/misc/scrape API path is deployed.
Risk and Exploitability
The CVSS score of 5.3 characterizes the vulnerability as moderate. An EPSS score of <1% indicates a low probability of exploitation in the current window. It is not listed in the CISA KEV catalog. Attackers must authenticate to the API; after authentication they can submit a malicious URL. The backend then performs an HTTP request to the target., it can reach internal resources, loopback addresses, and cloud metadata services, thereby exposing internal URLs and potentially sensitive configuration information. In environments where the server can reach private networks, the risk rises.
OpenCVE Enrichment