Junglewise Threat Intelligence

CVE-2026-86259: OpenMAIC SSRF validation bypass in non-production builds

CVE-2026-86259 · Severity: high · CVSS 7.5 · Published 2026-09-06

Executive brief

OpenMAIC is a multi-agent interactive learning platform that integrates with cloud-based services for image generation and AI capabilities. In non-production builds, the application fails to properly validate server-side requests, allowing attackers to bypass security checks and access sensitive cloud metadata services (such as AWS, Azure, or GCP credential endpoints) without authentication. This could expose cloud credentials, API keys, and other sensitive infrastructure metadata.

Technical details

The vulnerability is a server-side request forgery (SSRF) validation bypass in OpenMAIC versions before 1.0.1. The `validateUrlForSSRF` function is disabled or bypassed in non-production builds, specifically in the image generation API endpoint (`/api/generate/image`). Attackers can supply arbitrary provider URLs via the `x-base-url` HTTP header or the `baseUrl` parameter to make the server perform requests to cloud instance metadata services (e.g., http://169.254.169.254/latest/meta-data/) without proper validation. No authentication is required. A successful exploit allows attackers to retrieve sensitive cloud credentials, API tokens, and infrastructure metadata. The fix is available in OpenMAIC 1.0.1 and later, which enables SSRF validation in all build configurations.

Affected products

  • THU-MAIC OpenMAIC before 1.0.1

Timeline

  • 2026-09-06: disclosed

References