CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-11449: Server-Side Request Forgery in haotian-liu/llava

7.5 CVSS

Description

A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validation of the path parameter. This flaw can lead to unauthorized network access, sensitive data exposure, and further exploitation within the network.

Classification

CVE ID: CVE-2024-11449

CVSS Base Severity: HIGH

CVSS Base Score: 7.5

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem Types

CWE-918 Server-Side Request Forgery (SSRF)

Affected Products

Vendor: haotian-liu

Product: haotian-liu/llava

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.12% (probability of being exploited)

EPSS Percentile: 32.43% (scored less or equal to compared to others)

EPSS Date: 2025-04-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-11449
https://huntr.com/bounties/e96aba28-d564-4ecb-ab77-350511d2e1ee

Timeline