CVE-2026-108850 PUBLISHED

Company Research Agent through 2.2.0 SSRF via /generate-pdf ReportLab Markup

Assigner: VulnCheck
Reserved: 11.10.2026 Published: 11.10.2026 Updated: 11.10.2026

Company Research Agent through 2.2.0 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger outbound requests by injecting unescaped ReportLab paragraph markup into the /generate-pdf endpoint. Attackers can embed inline img elements in report_content to make the server fetch internal or external hosts, leaking image responses in returned PDFs and probing reachability.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor guy-hartstein
Product company-research-agent
Versions Default: unaffected
  • affected from 0 to 2.2.0 (incl.)

Credits

  • hieuPenguinnn finder

References

Problem Types

  • Server-Side Request Forgery (SSRF) CWE