PT-2025-12107 · Llava · Llava

Published

2025-03-20

·

Updated

2025-07-14

·

CVE-2024-11449

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions haotian-liu/llava version 1.2.0
Description A vulnerability allows for Server-Side Request Forgery (SSRF) through the "/run/predict" endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validation of the path parameter. This flaw can lead to unauthorized network access, sensitive data exposure, and further exploitation within the network.
Recommendations For haotian-liu/llava version 1.2.0, consider disabling access to the "/run/predict" endpoint until a patch is available. Restricting the use of the path parameter in this endpoint can also help minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-11449

Affected Products

Llava