CVE-2026-108719

Published: Ott 11, 2026 Last Modified: Ott 11, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,3
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 5,0
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: changed
Confidentiality: none
Integrity: low
Availability: none

Description

AI Translation Available

LLMGateway through 1.20.0 contains a blind server-side request forgery vulnerability that allows API key holders to reach internal hosts via the video-generation callback_url extension. Attackers can supply loopback, private, or cloud-metadata URLs that deliverWebhook POSTs to without the assertSafeWebhookTarget check, reaching internal services from the worker's network.

918

Server-Side Request Forgery (SSRF)

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Access Control
Potential Impacts:
Read Application Data Execute Unauthorized Code Or Commands Bypass Protection Mechanism
Applicable Platforms
Technologies: Web Based, AI/ML, Web Server
View CWE Details
https://github.com/theopenco/llmgateway
https://github.com/theopenco/llmgateway/blob/c84ba987da18edd80358a3450ccaea75c5…
https://github.com/theopenco/llmgateway/blob/c84ba987da18edd80358a3450ccaea75c5…
https://github.com/theopenco/llmgateway/blob/c84ba987da18edd80358a3450ccaea75c5…
https://hackmd.io/@haind03/theopenco-llmgateway-video-callback-ssrf-no-egress-g…
https://www.vulncheck.com/advisories/llmgateway-through-1.20.0-blind-ssrf-via-v…