Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-103243

MEDIUM NVD
CVSS Score 5.8
Severity MEDIUM
Published Sep 30, 2026
Vendor unknown

Description

LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.

References