CVE-2024-11449

A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validation of the path parameter. This flaw can lead to unauthorized network access, sensitive data exposure, and further exploitation within the network.
References
Link Resource
https://huntr.com/bounties/e96aba28-d564-4ecb-ab77-350511d2e1ee Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:hliu:large_language_and_vision_assistant:1.2.0:*:*:*:*:*:*:*

History

14 Jul 2025, 17:36

Type Values Removed Values Added
References () https://huntr.com/bounties/e96aba28-d564-4ecb-ab77-350511d2e1ee - () https://huntr.com/bounties/e96aba28-d564-4ecb-ab77-350511d2e1ee - Exploit, Third Party Advisory
First Time Hliu large Language And Vision Assistant
Hliu
Summary
  • (es) Una vulnerabilidad en haotian-liu/llava versión 1.2.0 (LLaVA-1.6) permite Server-Side Request Forgery (SSRF) a través del endpoint /run/predict. Un atacante puede obtener acceso no autorizado a las redes internas o al endpoint de metadatos de AWS mediante el envío de solicitudes manipuladas que aprovechan la validación insuficiente del parámetro path. Esta falla puede provocar acceso no autorizado a la red, la exposición de datos confidenciales y una mayor explotación dentro de la red.
CPE cpe:2.3:a:hliu:large_language_and_vision_assistant:1.2.0:*:*:*:*:*:*:*

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-14 17:36


NVD link : CVE-2024-11449

Mitre link : CVE-2024-11449

CVE.ORG link : CVE-2024-11449


JSON object : View

Products Affected

hliu

  • large_language_and_vision_assistant
CWE
CWE-918

Server-Side Request Forgery (SSRF)