Executive brief
vLLM is a large language model serving framework that processes user-supplied URLs to load media content (images, audio, video) for multimodal AI models. A vulnerability in its MediaConnector class allows attackers to force the vLLM server to make requests to internal network resources, internal services, or localhost endpoints it should not access. In containerized environments, this could enable attackers to scan internal networks, disrupt other services, exfiltrate data, or trigger false scaling decisions that destabilize operations.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) in the MediaConnector.load_from_url and load_from_url_async methods, which fetch media from user-provided URLs without adequate host restrictions. The vulnerable code directly processes HTTP, HTTPS, and file scheme URLs, accepting any URL the user supplies, including those pointing to internal IPs (127.0.0.1, 10.0.0.x) or localhost endpoints. An attacker requires low privileges (authenticated user) and moderate attack complexity but no user interaction. Exploitation allows access to internal services, network reconnaissance, denial of service against internal endpoints, and potential data exfiltration. The fix involves using the --allowed-media-domains option to restrict domains. The vulnerability affects vLLM versions 0.5.0 through 0.10.2, with a patch available in version 0.11.0.
Affected products
- vLLM vLLM 0.5.0 through 0.10.2
Timeline
- 2025-10-07: disclosed
- 2025-10-07: patched: Fix available in version 0.11.0