PT-2026-85555 · Marqo Ai · Marqo
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Marqo 2.26.0 contains a server-side request forgery vulnerability in the add documents endpoint that allows unauthenticated attackers to trigger requests to arbitrary URLs by supplying malicious media field values. Attackers can exploit download image from url and fetch content sample functions which lack destination filtering and host validation to access internal services and cloud metadata endpoints.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marqo