Product
LLaMA-Factory is vulnerable to server-side request forgery (SSRF) due to improper validation of multimodal media URLs in its OpenAI-compatible API, allowing unauthenticated attackers to access internal network resources.