VYPR
Vendor

Apify

Products
5
CVEs
4
Across products
5
Status
Private

Products

5

Recent CVEs

4
  • CVE-2026-81093HigAug 27, 2026
    risk 0.49cvss 8.6epss 0.01

    The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/common/get_html_skeleton.ts validated the url argument with isValidHttpUrl from src/utils/generic.ts, which confirmed the string began with an http or https…

  • CVE-2026-50143HigAug 18, 2026
    risk 0.46cvss 8.1epss 0.00

    The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the trusted Actor standby URL with the…

  • CVE-2026-46341MedJul 16, 2026
    risk 0.33cvss 6.1epss 0.00

    The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.9.21, the fetch-apify-docs tool in src/tools/common/fetch_apify_docs.ts validates allowlisted documentation…

  • CVE-2026-46497LowJun 10, 2026
    risk 0.08cvss —epss 0.00

    Crawlee is a web scraping and browser automation library. From version 1.0.0 to before version 1.7.0, Crawlee is vulnerable to SSRF via sitemap-derived URLs. This issue has been patched in version 1.7.0.