Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

ms-swift 4.5.2 SSRF via unvalidated media URLs

ms-swift 4.5.2 contains a server-side request forgery vulnerability in its OpenAI-compatible API that fetches multimodal media URLs without proper validation. Unauthenticated attackers can supply arbitrary image_url, audio_url, or video_url parameters to make the server access internal services and cloud metadata endpoints.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers can exploit SSRF to access internal services and cloud metadata endpoints by supplying arbitrary media URLs

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-hrmr-fv6h-885h