GHSA-26q6-mgpf-f836MediumCVSS 5.8

LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal...

Published
September 30, 2026
Last Modified
September 30, 2026

🔗 CVE IDs covered (1)

📋 Description

LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.

🔗 References (7)