medium · CVSS v3 5.8 · CVSS v4 6.9
CVE-2026-103243
LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenti…
Description
LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.8
- CVSS v4
- 6.9
- EPSS
- —