Server-Side Request Forgery in LightLLM from ModelTC
CVE-2026-103243
6.9MEDIUM
What is CVE-2026-103243?
The vulnerability in LightLLM versions up to 1.2.0 arises from insufficient validation of the image_url and audio_url parameters in multimodal endpoints. This flaw allows unauthenticated attackers to perform server-side request forgery (SSRF), enabling them to submit arbitrary URLs. Consequently, attackers can compel the server to fetch internal resources, potentially disclosing sensitive internal content or yielding error messages that reveal the internal network architecture.
Affected Version(s)
LightLLM 0 <= 1.2.0
