{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/llama-factory/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:llama_factory:llama_factory:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85673"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LLaMA-Factory (unspecified version)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["LLaMA-Factory"],"content_html":"\u003cp\u003eLLaMA-Factory contains a server-side request forgery (SSRF) vulnerability within its OpenAI-compatible API's multimodal media URL handler (CVE-2026-85673). The issue stems from the 'check_ssrf_url' guard, which performs a one-time validation of the user-supplied URL. However, the application uses 'requests.get' to fetch these URLs, which follows HTTP redirects and performs subsequent DNS resolutions without re-validating the final, resolved destination. This flaw permits unauthenticated attackers to bypass security controls using techniques such as HTTP redirection or DNS rebinding. By exploiting this, attackers can force the LLaMA-Factory instance to perform requests to sensitive internal network addresses or cloud metadata service endpoints, potentially leading to unauthorized data access or internal reconnaissance.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to interact with internal network services that are otherwise inaccessible from the public internet. This includes access to cloud metadata services (e.g., 169.254.169.254), internal management interfaces, and other microservices within the hosting environment. The potential impact involves unauthorized data exfiltration, service manipulation, or leveraging the application as a proxy for lateral movement within the infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor application logs for anomalous outbound HTTP requests originating from the LLaMA-Factory server, particularly those targeting internal IP ranges or cloud metadata endpoints.\u003c/li\u003e\n\u003cli\u003eImplement network-level egress filtering to prevent the LLaMA-Factory application from reaching sensitive internal segments or the cloud provider metadata service.\u003c/li\u003e\n\u003cli\u003eReview vendor documentation for patches addressing CVE-2026-85673 and update the LLaMA-Factory deployment to a non-vulnerable version as soon as one is released.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:30:57Z","date_published":"2026-09-04T15:30:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-llama-factory-ssrf/","summary":"LLaMA-Factory is vulnerable to server-side request forgery (SSRF) due to improper validation of multimodal media URLs in its OpenAI-compatible API, allowing unauthenticated attackers to access internal network resources.","title":"CVE-2026-85673: SSRF Vulnerability in LLaMA-Factory OpenAI-Compatible API","url":"https://feed.craftedsignal.io/briefs/2026-09-llama-factory-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - LLaMA-Factory","version":"https://jsonfeed.org/version/1.1"}