Blind Server-Side Request Forgery in LLMGateway by TheOpenCo
CVE-2026-108719

5.3MEDIUM

Key Information:

Vendor

Theopenco

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108719?

The LLMGateway, up to version 1.20.0, is susceptible to a blind server-side request forgery (SSRF) vulnerability, allowing attackers holding an API key to exploit the system. The flaw originates from the video-generation callback_url extension, where malicious actors can provide internal loopback, private, or cloud-metadata URLs. This enables unwanted Webhook POST requests to be sent to internal services, bypassing the necessary assertSafeWebhookTarget safety check. Consequently, this vulnerability opens the door for internal network services to be exposed and manipulated.

Affected Version(s)

LLMGateway 0 <= 1.20.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.