CVE-2026-103243: LightLLM through 1.2.0 Server-Side Request Forgery via multimodal endpoints
LightLLM through 1.2.0 fails to validate imageurl and audiourl parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
LightLLM deployments through version 1.2.0 are exposed when multimodal endpoints accept image_url or audio_url parameters. The issue is reachable remotely and does not require authentication or user interaction.
What does an attacker need to exploit this issue?
An attacker only needs network access to a vulnerable multimodal endpoint and the ability to submit an arbitrary image_url or audio_url value. Exploitation is low complexity and requires no privileges.
What could an attacker access through the SSRF?
The server can be induced to fetch arbitrary URLs, including internal resources reachable from the LightLLM host. Vision-model processing may disclose fetched content, while error responses may reveal internal network topology.
How can I determine whether my instance is affected?
Check whether the deployed LightLLM version is 1.2.0 or earlier and whether its multimodal endpoints accept image_url or audio_url inputs. The vulnerable behavior is the absence of URL validation before the server fetches those resources.