CVE-2026-103243

LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.

  • Published Sep 30, 2026
  • CVSS 6.9 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-103243 at the National Vulnerability Database