ms-swift 4.5.2 SSRF via unvalidated media URLs
ms-swift 4.5.2 contains a server-side request forgery vulnerability in its OpenAI-compatible API that fetches multimodal media URLs without proper validation. Unauthenticated attackers can supply arbitrary image_url, audio_url, or video_url parameters to make the server access internal services and cloud metadata endpoints.
Disclosed 4 September 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers can exploit SSRF to access internal services and cloud metadata endpoints by supplying arbitrary media URLs
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-hrmr-fv6h-885h
