VYPR

refly

by Refly AI

CVEs (1)

  • CVE-2026-91199MedSep 14, 2026
    risk 0.33cvss 5.0epss

    Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address. Authenticated attackers can make the backend issue requests to loopback,…