A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validation of the path parameter. This flaw can lead to unauthorized network access, sensitive data exposure, and further exploitation within the network.
References
Link | Resource |
---|---|
https://huntr.com/bounties/e96aba28-d564-4ecb-ab77-350511d2e1ee | Exploit Third Party Advisory |
Configurations
History
14 Jul 2025, 17:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://huntr.com/bounties/e96aba28-d564-4ecb-ab77-350511d2e1ee - Exploit, Third Party Advisory | |
First Time |
Hliu large Language And Vision Assistant
Hliu |
|
Summary |
|
|
CPE | cpe:2.3:a:hliu:large_language_and_vision_assistant:1.2.0:*:*:*:*:*:*:* |
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-07-14 17:36
NVD link : CVE-2024-11449
Mitre link : CVE-2024-11449
CVE.ORG link : CVE-2024-11449
JSON object : View
Products Affected
hliu
- large_language_and_vision_assistant
CWE
CWE-918
Server-Side Request Forgery (SSRF)