VYPR
High severity8.5NVD Advisory· Published Sep 14, 2026· Updated Sep 14, 2026

CVE-2026-91079

CVE-2026-91079

Description

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to internal metadata services and network hosts.

Affected products

2
  • Huly/Platformreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=0.7.426

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.