Server-side Request Forgery Vulnerability in Marqo 2.26.0
CVE-2026-85662
6.9MEDIUM
What is CVE-2026-85662?
The Marqo version 2.26.0 is susceptible to a server-side request forgery (SSRF) vulnerability within the add_documents endpoint. Unauthenticated attackers can manipulate the media field values to initiate requests to arbitrary URLs. By exploiting the inadequate filtering and lack of host validation in the download_image_from_url and fetch_content_sample functions, attackers can potentially access internal services and cloud metadata endpoints, leading to unauthorized data exposure.
Affected Version(s)
marqo 0 <= 2.26.0
