Executive brief
LLaMA-Factory is an open-source framework for fine-tuning large language and vision models that includes an OpenAI-compatible API. A server-side request forgery (SSRF) vulnerability in its multimodal media URL handler allows unauthenticated attackers to bypass security controls and access internal services and cloud metadata endpoints. This could expose sensitive configuration, credentials, or internal system information.
Technical details
The vulnerability exists in the OpenAI-compatible API's multimodal media URL handler due to ineffective SSRF validation. The check_ssrf_url guard validates URLs once, but the underlying requests.get call follows HTTP redirects and re-resolves DNS without re-validating the final destination. Attackers can exploit this through HTTP redirect chains or DNS rebinding attacks to access internal-only addresses and cloud metadata endpoints (e.g., AWS, GCP metadata services) that would normally be blocked. No authentication is required; the API is network-accessible. The fix involves validating the final URL after all redirects and DNS resolutions are complete.
Affected products
- hiyouga LLaMA-Factory before fix (v0.9.5 and earlier vulnerable)
Timeline
- 2026-09-04: disclosed: CVE-2026-85673 published
- 2026-09-04: other: Reported severity: high, CVSS 7.5