CVE-2026-91199: Refly through 1.1.0 Server-Side Request Forgery via scrape endpoint

Published Sep 14, 2026
·
Updated

Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address. Authenticated attackers can make the backend issue requests to loopback, private, and link-local addresses including cloud metadata services to read page titles and descriptions of internal resources.

Affected Software

1 affected component
Refly<=1.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Refly to a version that resolves this vulnerability.

    Fixed in 1.1.0

Event History

Sep 14, 2026
CVE Published
via MITRE·10:10 PM
Data Sourced
via MITRE·10:10 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs to be authenticated and able to send a POST request to the /v1/misc/scrape endpoint. No user interaction is required, and the attack can be performed remotely.

2

What systems or data can the attacker reach?

The backend can be induced to request caller-supplied loopback, private, and link-local addresses, including cloud metadata services. The exposed result is limited to page titles and descriptions returned from those internal resources.

3

Are default URL restrictions effective against this endpoint?

No validation is performed for the supplied URL's scheme, host, or resolved address. As a result, requests are not restricted from targeting internal or link-local network locations.

4

How can I determine whether my deployment is affected?

Deployments of Refly through version 1.1.0 are affected if authenticated users can access POST /v1/misc/scrape. Review whether the endpoint accepts user-controlled URLs and whether it can reach loopback, private, link-local, or cloud metadata addresses from the server environment.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203