PT-2025-41177 · Vllm · Vllm

CVE-2025-6242

·

Published

2025-10-07

·

Updated

2026-07-07

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions vLLM (affected versions not specified)
Description An issue exists within the MediaConnector class in the vLLM project’s multimodal feature set. Specifically, the load from url and load from url async methods do not sufficiently restrict the target hosts when fetching and processing media from URLs provided by users. This can allow an attacker to force the vLLM server to make requests to arbitrary internal network resources, resulting in a Server-Side Request Forgery (SSRF).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-6242
GHSA-3F6C-7FW2-PPM4
PYSEC-2026-2011

Affected Products

Vllm