CVE-2026-108850
Received Received - Intake

Server-Side Request Forgery in Company Research Agent PDF Generator

Vulnerability report for CVE-2026-108850, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Company Research Agent through 2.2.0 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger outbound requests by injecting unescaped ReportLab paragraph markup into the /generate-pdf endpoint. Attackers can embed inline img elements in report_content to make the server fetch internal or external hosts, leaking image responses in returned PDFs and probing reachability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
guy-hartstein company-research-agent 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a server-side request forgery (SSRF) in Company Research Agent through version 2.2.0. It allows unauthenticated attackers to make the server send outbound requests by injecting unescaped ReportLab paragraph markup into the /generate-pdf endpoint. Attackers can embed inline img elements in report_content to force the server to fetch internal or external hosts. The responses from these requests are leaked in the returned PDFs, which can be used to probe network reachability.

Detection Guidance

To detect this vulnerability, monitor outbound requests from the Company Research Agent server, particularly those triggered by PDF generation. Check logs for unexpected connections to internal or external hosts initiated by the /generate-pdf endpoint. Look for embedded img elements in report_content that may indicate SSRF attempts.

Impact Analysis

This vulnerability can impact you by allowing attackers to access internal systems or external hosts through your server. They can probe your network, extract sensitive information via leaked image responses, or use the server as a proxy to bypass firewalls. This could lead to data breaches, unauthorized access, or further attacks on your infrastructure.

Compliance Impact

This vulnerability can lead to non-compliance with GDPR and HIPAA by enabling unauthorized access to sensitive data. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. A breach via this SSRF could result in data leaks, violating these regulations and potentially leading to legal penalties, fines, or reputational damage.

Mitigation Strategies

Immediately update Company Research Agent to the latest version beyond 2.2.0. Restrict network access to the /generate-pdf endpoint using firewalls or WAF rules. Disable or sanitize ReportLab paragraph markup input to prevent img element injection. Monitor for unusual outbound traffic patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108850. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart