Database/AI/ML frameworks & serving

LocalAI (`/models/apply`): Unauthenticated SSRF fetching arbitrary internal URLs
CVSS 8.6CVE-2026-59707AI/ML frameworks & servingcurated
Impact
Unauthenticated SSRF fetching arbitrary internal URLs
Who can reach it
Unauthenticated network to the model-install endpoint
What to do
Upgrade; block egress to internal ranges and IMDS
References
Related entries
- LocalAI (`/models/apply`): SSRF and partial local file inclusionCVE-2024-6095 · LocalAI (`/models/apply`)Medium
- Text Generation Inference (TGI): SSRF in the OpenAI-compatible multimodal chat endpointCVE-2026-63086 · Text Generation Inference (TGI)High
- MLflow: a crafted model artifact runs arbitrary code when the model is loadedCVE-2026-79721 · MLflow (model artifact loading)High
- Vocos: model config can name any importable class, so from_pretrained runs the repo owner's codeCVE-2026-79784 · Vocos (instantiate_class in vocos/pretrained.py)High
- iFlytek astron-agent: copyFlow lacks an ownership check, letting any tenant read or overwrite workflowsCVE-2026-82475 · iFlytek astron-agent (console backend copyFlow workflow endpoint)High
- Unsloth Zoo: model config.json injects Python that runs via exec() when a model is loadedCVE-2026-93348 · Unsloth / Unsloth Zoo (get_transformers_model_type model-loading compile path)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.