VYPR
Medium severityNVD Advisory· Published Jun 24, 2026· Updated Jun 25, 2026

CVE-2026-13150

CVE-2026-13150

Description

Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) in ccyl13 Pentestify 1.0.0 and lower allows remote attackers to make the server issue requests to arbitrary internal or external URLs, including cloud metadata services, and return the rendered content in the resulting PDF via a crafted Host header, because the target URL is built from request.base_url without validation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Ccyl13/Pentestifyinferred2 versions
    <=1.0.0+ 1 more
    • (no CPE)range: <=1.0.0
    • (no CPE)range: <=1.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.