{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aogxogx/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ogx:ogx:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85666"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OGX (commit \u003c= fbe8e0f)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OGX"],"content_html":"\u003cp\u003eOGX (formerly Llama Stack), up to commit fbe8e0f, contains a critical server-side request forgery (SSRF) vulnerability in its OpenAI-compatible POST /v1/responses endpoint. The vulnerability stems from the MCP tool definition processing logic, where the server_url parameter is fetched server-side without performing necessary destination validation. Specifically, the validate_url_not_private() guard, which is correctly implemented for other input fields, is omitted for the server_url parameter.\u003c/p\u003e\n\u003cp\u003eIn default configurations that lack authentication, a remote, unauthenticated attacker can exploit this flaw to force the OGX server to initiate connections to arbitrary internal network resources. This includes sensitive cloud metadata endpoints such as 169.254.169.254. Furthermore, the vulnerability allows for the forwarding of attacker-supplied headers and bearer tokens to these internal destinations, potentially leading to unauthorized data exfiltration or internal system interaction. This vulnerability represents a high risk for deployments residing in cloud environments where metadata services contain IAM credentials or sensitive configuration information.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to bypass network perimeters and interact with internal-only services. In cloud-native deployments, this typically results in the exfiltration of sensitive cloud metadata (e.g., IAM role credentials, instance metadata), which can be leveraged for lateral movement or full compromise of the cloud account.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update all OGX instances to a version beyond commit fbe8e0f.\u003c/li\u003e\n\u003cli\u003eImplement strict network egress filtering on all servers hosting the OGX platform to prevent connections to internal IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, and 169.254.169.254).\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect abnormal POST requests to the affected endpoint.\u003c/li\u003e\n\u003cli\u003eApply the following Sigma rule to your webserver access logs to identify exploitation attempts targeting the v1/responses endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:28:55Z","date_published":"2026-09-04T15:28:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ogx-ssrf/","summary":"OGX contains an unauthenticated Server-Side Request Forgery vulnerability in the POST /v1/responses endpoint, allowing remote attackers to probe internal cloud metadata services.","title":"Unauthenticated Server-Side Request Forgery in OGX","url":"https://feed.craftedsignal.io/briefs/2026-09-ogx-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ogx:ogx:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}