Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15143

Опубликовано: 10 июл. 2026
Источник: redhat
CVSS3: 9.3

Описание

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially resulting in sensitive information disclosure, such as cloud provider credentials or access to internal network services.

Отчет

This vulnerability is rated as Important. It allows an attacker with network access to the detector service to perform Server-Side Request Forgery (SSRF) and local file reads. This is due to the guardrails-detectors component accepting arbitrary XML Schema Definition (XSD) strings, which are then processed by the xmlschema library without restricting external schemaLocation references. This could lead to credential theft or access to internal services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-built-in-detector-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-guardrails-detector-huggingface-runtime-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2498165guardrails-detectors: guardrails-detectors: SSRF and local file read via user-supplied XML Schema (xml-with-schema:)

9.3 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.3
nvd
около 1 месяца назад

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially resulting in sensitive information disclosure, such as cloud provider credentials or access to internal network services.

CVSS3: 9.3
github
около 1 месяца назад

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially resulting in sensitive information disclosure, such as cloud provider credentials or access to internal network services.

9.3 Critical

CVSS3