Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-6242

Опубликовано: 07 окт. 2025
Источник: debian
EPSS Низкий

Описание

A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set. The load_from_url and load_from_url_async methods fetch and process media from user-provided URLs without adequate restrictions on the target hosts. This allows an attacker to coerce the vLLM server into making arbitrary requests to internal network resources.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vllmitppackage

EPSS

Процентиль: 23%
0.00075
Низкий

Связанные уязвимости

CVSS3: 7.1
nvd
4 месяца назад

A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set. The load_from_url and load_from_url_async methods fetch and process media from user-provided URLs without adequate restrictions on the target hosts. This allows an attacker to coerce the vLLM server into making arbitrary requests to internal network resources.

CVSS3: 7.1
github
4 месяца назад

vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class

EPSS

Процентиль: 23%
0.00075
Низкий