Database/AI/ML frameworks & serving
Text Generation Inference (TGI): SSRF in the OpenAI-compatible multimodal chat endpoint
CVSS 8.6CVE-2026-63086AI/ML frameworks & servingcurated
Impact
SSRF in the OpenAI-compatible multimodal chat endpoint
Who can reach it
Unauthenticated request supplying an image URL
What to do
Upgrade past 3.3.7 and block metadata/internal egress from serving pods
References
Related entries
- MLflow: a crafted model artifact runs arbitrary code when the model is loadedCVE-2026-79721 · MLflow (model artifact loading)High
- Vocos: model config can name any importable class, so from_pretrained runs the repo owner's codeCVE-2026-79784 · Vocos (instantiate_class in vocos/pretrained.py)High
- iFlytek astron-agent: copyFlow lacks an ownership check, letting any tenant read or overwrite workflowsCVE-2026-82475 · iFlytek astron-agent (console backend copyFlow workflow endpoint)High
- Unsloth Zoo: model config.json injects Python that runs via exec() when a model is loadedCVE-2026-93348 · Unsloth / Unsloth Zoo (get_transformers_model_type model-loading compile path)High
- Ollama: agent-mode Bash approval does not parse shell syntax, so appended commands run unapprovedCVE-2026-102697 · Ollama experimental agent mode (Bash tool approval parser, x/agent/approval.go)High
- Qdrant (`/logger`): Append to arbitrary files via the logger endpointCVE-2026-25628 · Qdrant (`/logger`)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.