CVE-2025-6242

A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set. The load_from_url and load_from_url_async methods fetch and process media from user-provided URLs without adequate restrictions on the target hosts. This allows an attacker to coerce the vLLM server into making arbitrary requests to internal network resources.
Configurations

No configuration.

History

07 Oct 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-07 20:15

Updated : 2025-10-08 19:38


NVD link : CVE-2025-6242

Mitre link : CVE-2025-6242

CVE.ORG link : CVE-2025-6242


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)