VYPR

Platform

by Huly

Source repositories

CVEs (8)

  • CVE-2026-91079HigSep 14, 2026
    risk 0.55cvss 8.5epss 0.00

    Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as…

  • CVE-2024-48450MedOct 25, 2024
    risk 0.42cvss 6.5epss 0.01

    An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into chat group.

  • CVE-2026-5623MedApr 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/front/src/index.ts of the component Import Endpoint. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit is…

  • CVE-2026-12213MedJun 15, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in hcengineering Huly Platform up to 0.7.0. Affected by this vulnerability is the function getAccountInfo of the file server/account/src/operations.ts of the component User Information Handler. The manipulation results in improper authorization. The…

  • CVE-2026-12212MedJun 15, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in hcengineering Huly Platform up to 0.7.0. Affected is the function getMailboxSecret of the file server/account/src/operations.ts of the component RPC Interface. The manipulation leads to improper access controls. The attack may be initiated…

  • CVE-2024-27707MedMar 7, 2024
    risk 0.28cvss 4.3epss 0.00

    Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbitrary code via upload of crafted SVG file.

  • CVE-2026-5622LowApr 6, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functionality of the file foundations/core/packages/token/src/token.ts of the component JWT Token Handler. This manipulation of the argument SERVER_SECRET with the input…

  • CVE-2026-56769HigJun 25, 2026
    risk 0.00cvss 8.5epss 0.00

    Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerability in the /import endpoint of front pod that allows workspace users to make arbitrary server requests. Attackers can exploit this by supplying malicious URLs…