CVE-2026-103243 Details
Description
LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.
A server-side request forgery (SSRF) vulnerability has been identified in LightLLM versions through 1.2.0. The issue arises because the application fails to properly validate 'image_url' and 'audio_url' parameters in multimodal endpoints. This oversight allows unauthenticated attackers to send arbitrary URLs that the server will fetch, potentially accessing internal resources. The fetched content can be processed by the vision model, which may disclose sensitive information, or generate error responses that reveal details about the internal network topology.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ModelTC/LightLLM | [email protected] | Vendor |
| https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/multimodal_params.py#L149 | [email protected] | Source CodeVendor |
| https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/utils/multimodal_utils.py#L82-L91 | [email protected] | Source CodeVendor |
| https://github.com/ModelTC/LightLLM/issues/1608 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/lightllm-through-1.2.0-server-side-request-forgery-via-multimodal-endpoints | [email protected] | AdvisoryBundleVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ModelTC LightLLM | <= 1.2.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion