VYPR

Automatisch

by Automatisch

Source repositories

CVEs (2)

  • CVE-2026-72566HigAug 10, 2026
    risk 0.50cvss 7.7epss 0.00

    A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow' permission to make the server fetch arbitrary URLs and retrieve the full response body via the HTTP Request app's Custom Request…

  • CVE-2026-81033MedAug 26, 2026
    risk 0.34cvss 5.3epss

    Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/controllers/internal/api/v1/users/forgot-password.js looks the address up and chains a not-found throw onto the query, so an address…