PT-2026-103285 · Modeltc · Lightllm

·

CVE-2026-103243

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
LightLLM through 1.2.0 fails to validate image url and audio url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103243

Affected Products

Lightllm