Sceawere
Vulnerability Detail
CVE-2026-108719UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LLMGateway SSRF via Callback URL
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5
- Creation Date
- 4h ago
- Vendor
- theopenco
- Product
- LLMGateway
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
LLMGateway through 1.20.0 contains a blind server-side request forgery vulnerability that allows API key holders to reach internal hosts via the video-generation callback_url extension. Attackers can supply loopback, private, or cloud-metadata URLs that deliverWebhook POSTs to without the assertSafeWebhookTarget check, reaching internal services from the worker's network.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.0",
"pubDate": "2026-10-11T13:17:15.163Z",
"pubdate": "2026-10-11T13:17:15.163Z",
"executiveSummary": "LLMGateway versions through 1.20.0 are susceptible to a Blind Server-Side Request Forgery (SSRF) vulnerability. The flaw exists within the video-generation callback_url extension, which fails to adequately sanitize user-supplied URLs before processing them.\nThe vulnerability allows authenticated API key holders to bypass network security controls and initiate outbound requests to arbitrary destinations, including loopback addresses (127.0.0.1), private RFC 1918 network ranges, and cloud provider metadata services (e.g., 169.254.169.254).\nBy omitting the necessary assertSafeWebhookTarget validation, the application enables an attacker to force the internal worker service to perform unintended HTTP POST requests. This facilitates unauthorized interaction with internal infrastructure that is otherwise protected by network perimeters. The impact includes potential data exfiltration, internal service exploitation, and the potential compromise of cloud instance credentials if metadata services are queried successfully. Exploitation requires valid API key credentials, making this an authenticated attack vector that leverages excessive trust in user-provided callback configurations.",
"technicalDetails": "The vulnerability resides in the video-generation processing pipeline of LLMGateway, specifically within the logic handling the callback_url parameter. The root cause is an improper validation sequence where the application performs an outbound request to a user-supplied URI without first invoking the assertSafeWebhookTarget function, which is designed to filter out unauthorized or dangerous endpoints.\nThe attack flow proceeds as follows: An authenticated user with a valid API key submits a request to trigger video generation, providing a malicious callback_url. Instead of a legitimate public endpoint, the attacker specifies a target within the internal network, such as an internal management interface, a database, or the cloud metadata service instance. The LLMGateway worker node receives this request and, failing the required security check, proceeds to initiate an asynchronous webhook POST operation to the attacker-specified URL.\nBecause the server initiates the request on behalf of the user, the traffic originates from the worker's internal IP address. This effectively bypasses network-level access control lists (ACLs) or firewalls that assume internal traffic is trusted. The blind nature of the SSRF means the attacker may not see the direct response body in the API output, but they can observe side-channel effects—such as timing differences, error messages indicating connection success, or downstream changes in application state—to confirm the delivery of the POST payload to internal services.\nExploitation involves crafting a callback_url that targets high-value internal targets. For instance, querying the cloud metadata endpoint can result in the retrieval of IAM role credentials or instance metadata. Similarly, targeting internal REST APIs could allow an attacker to trigger actions on unauthenticated internal services. The vulnerability is present in all LLMGateway versions up to 1.20.0. The lack of strict protocol and destination validation effectively turns the callback functionality into a proxy for arbitrary internal scanning and exploitation, granting an attacker the network privilege level of the worker node itself."
}