---
id: CVE-2026-91079
title: >-
  Huly Platform through 0.7.426 contains a server-side request forgery
  vulnerability in the print service due to missing hostname allowlist
  validation
summary: >-
  Huly Platform through 0.7.426 contains a server-side request forgery
  vulnerability in the print service due to missing hostname allowlist
  validation. Authenticated workspace members can supply arbitrary URLs to the
  print endpoint, which …
severity: high
cvss: 8.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'
cwe:
  - CWE-918
vendor: hcengineering
product: platform
affected:
  - platform <= 0.7.426
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:17:03.600'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91079'
references:
  - url: 'https://github.com/hcengineering/platform'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/hcengineering/platform/blob/v0.7.426/services/print/pod-print/src/config.ts
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/hcengineering/platform/blob/v0.7.426/services/print/pod-print/src/server.ts
    label: disclosure@vulncheck.com
  - url: 'https://github.com/hcengineering/platform/issues/10908'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/huly-platform-through-0.7.426-ssrf-via-print-service
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T19:20:46.593809Z'
ingestedAt: '2026-09-14T19:13:23.464Z'
epss: 0.00353
epssPercentile: 0.29083
---

## Overview

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to internal metadata services and network hosts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
