Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

LLaMA-Factory SSRF vulnerability in OpenAI API handler

LLaMA-Factory contains a server-side request forgery vulnerability in its OpenAI-compatible API multimodal media URL handler. Unauthenticated attackers can bypass SSRF validation using HTTP redirects or DNS rebinding to access internal addresses and cloud metadata endpoints.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers can bypass SSRF validation to access internal addresses and cloud metadata endpoints

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-8g7q-h2wm-q974