CVE-2026-103243
LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.
- Published Sep 30, 2026
- CVSS 6.9 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)