Sceawere
Vulnerability Detail
CVE-2026-108850UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SSRF via ReportLab Markup Injection
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- guy-hartstein
- Product
- company-research-agent
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Company Research Agent through 2.2.0 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger outbound requests by injecting unescaped ReportLab paragraph markup into the /generate-pdf endpoint. Attackers can embed inline img elements in report_content to make the server fetch internal or external hosts, leaking image responses in returned PDFs and probing reachability.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-11T14:17:04.530Z",
"pubdate": "2026-10-11T14:17:04.530Z",
"executiveSummary": "Company Research Agent versions up to and including 2.2.0 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability originating from improper input sanitization in the PDF generation process.\nThe vulnerability resides within the /generate-pdf endpoint, where the application processes user-supplied report_content without adequately sanitizing ReportLab paragraph markup.\nUnauthenticated attackers can exploit this flaw to force the server to initiate arbitrary outbound HTTP requests to internal or external network resources.\nSuccessful exploitation allows attackers to probe for internal service reachability and exfiltrate information by embedding malicious img tags within the report content, which are then rendered by the server.\nThe risk is critical as it bypasses network segmentation, potentially exposing internal infrastructure that is otherwise unreachable from the public internet.\nNo authentication is required to trigger the request, lowering the barrier for exploitation.",
"technicalDetails": "The root cause of this SSRF vulnerability is the failure to sanitize user-provided input before it is passed to the ReportLab library, which is utilized for PDF generation in the /generate-pdf endpoint.\nReportLab supports a subset of XML-like markup for styling, which includes the <img /> tag for embedding images in documents. Because the application fails to filter or escape this markup, attackers can inject arbitrary img tags into the report_content parameter.\nWhen the PDF generation engine parses the malicious report_content, it interprets the src attribute of the injected img element as a URI to be fetched. Consequently, the server-side process executes an outbound GET request to the specified URI to retrieve the image resource.\nThe attack flow proceeds as follows: First, the attacker crafts a malicious request targeting the /generate-pdf endpoint. Within the report_content field, the attacker includes a payload such as <img src=\"http://internal-service:port/sensitive-data\"/>. Upon submission, the backend application processes this string and attempts to resolve and fetch the content from the specified destination.\nBecause the server is performing the request, it can interact with services bound to 'localhost' or within the internal network segment that are not exposed to the public. If the target server returns an image or file that can be interpreted, the resulting PDF may include the retrieved data, effectively leaking information to the attacker.\nThis vulnerability is present in Company Research Agent version 2.2.0 and earlier. It requires no authentication, allowing any remote attacker with network access to the /generate-pdf endpoint to leverage the server as a proxy to perform reconnaissance on internal network infrastructure, potentially leading to unauthorized data exposure or secondary attacks against internal services."
}