CVE-2026-108719
MEDIUM
5,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
5,0
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: changed
Confidentiality: none
Integrity: low
Availability: none
Description
AI Translation Available
LLMGateway through 1.20.0 contains a blind server-side request forgery vulnerability that allows API key holders to reach internal hosts via the video-generation callback_url extension. Attackers can supply loopback, private, or cloud-metadata URLs that deliverWebhook POSTs to without the assertSafeWebhookTarget check, reaching internal services from the worker's network.
918
Server-Side Request Forgery (SSRF)
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Access Control
Potential Impacts:
Read Application Data
Execute Unauthorized Code Or Commands
Bypass Protection Mechanism
Applicable Platforms
Technologies:
Web Based, AI/ML, Web Server
https://github.com/theopenco/llmgateway
https://github.com/theopenco/llmgateway/blob/c84ba987da18edd80358a3450ccaea75c5…
https://github.com/theopenco/llmgateway/blob/c84ba987da18edd80358a3450ccaea75c5…
https://github.com/theopenco/llmgateway/blob/c84ba987da18edd80358a3450ccaea75c5…
https://hackmd.io/@haind03/theopenco-llmgateway-video-callback-ssrf-no-egress-g…
https://www.vulncheck.com/advisories/llmgateway-through-1.20.0-blind-ssrf-via-v…