Blind Server-Side Request Forgery in LLMGateway by TheOpenCo
CVE-2026-108719
5.3MEDIUM
What is CVE-2026-108719?
The LLMGateway, up to version 1.20.0, is susceptible to a blind server-side request forgery (SSRF) vulnerability, allowing attackers holding an API key to exploit the system. The flaw originates from the video-generation callback_url extension, where malicious actors can provide internal loopback, private, or cloud-metadata URLs. This enables unwanted Webhook POST requests to be sent to internal services, bypassing the necessary assertSafeWebhookTarget safety check. Consequently, this vulnerability opens the door for internal network services to be exposed and manipulated.
Affected Version(s)
LLMGateway 0 <= 1.20.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
