VYPR

company-research-agent

by Guy Hartstein

CVEs (1)

  • CVE-2026-108850MedOct 11, 2026
    risk 0.34cvss 5.3epss —

    Company Research Agent through 2.2.0 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger outbound requests by injecting unescaped ReportLab paragraph markup into the /generate-pdf endpoint. Attackers can embed inline img elements…