rootpwn

medium · CVSS v3 5.8 · CVSS v4 6.9

CVE-2026-103243

LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenti…

Description

LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.8
CVSS v4
6.9
EPSS
—

← All CVEs