PT-2025-41177 · Vllm · Vllm

Published

2025-10-07

·

Updated

2025-10-09

·

CVE-2025-6242

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions vLLM (affected versions not specified)
Description An issue exists within the MediaConnector class in the vLLM project’s multimodal feature set. Specifically, the load from url and load from url async methods do not sufficiently restrict the target hosts when fetching and processing media from URLs provided by users. This can allow an attacker to force the vLLM server to make requests to arbitrary internal network resources, resulting in a Server-Side Request Forgery (SSRF).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-6242
GHSA-3F6C-7FW2-PPM4

Affected Products

Vllm