PT-2025-12107 · Llava · Llava
Published
2025-03-20
·
Updated
2025-07-14
·
CVE-2024-11449
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
haotian-liu/llava version 1.2.0
Description
A vulnerability allows for Server-Side Request Forgery (SSRF) through the "/run/predict" endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validation of the
path parameter. This flaw can lead to unauthorized network access, sensitive data exposure, and further exploitation within the network.Recommendations
For haotian-liu/llava version 1.2.0, consider disabling access to the "/run/predict" endpoint until a patch is available. Restricting the use of the
path parameter in this endpoint can also help minimize the risk of exploitation.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Llava