Executive brief
knowns is an open-source platform for managing and querying data embeddings. A vulnerability in the embedding model testing endpoint allows attackers to make the server send requests to arbitrary network destinations, enabling them to probe internal networks and cloud metadata services. This could expose sensitive internal infrastructure information and compromise cloud credentials.
Technical details
The vulnerability is a server-side request forgery (SSRF) in the POST /api/embedding-models/test endpoint, which accepts caller-supplied URLs and issues outbound HTTP requests without proper validation. An attacker can enumerate internal hosts and cloud metadata endpoints (e.g., AWS metadata services) by observing transport error messages that reveal network reachability. The vulnerability requires only network access to the endpoint; no authentication is explicitly mentioned as a prerequisite. An attacker can map internal network topology and potentially retrieve sensitive metadata. Patches should implement URL validation to block requests to private IP ranges and cloud metadata endpoints.
Affected products
- knowns knowns through 0.33.0
Timeline
- 2026-09-07: disclosed