A Server-Side Request Forgery (SSRF) vulnerability exists...
Moderate severity
Unreviewed
Published
Mar 20, 2025
to the GitHub Advisory Database
•
Updated Mar 20, 2025
Description
Published by the National Vulnerability Database
Mar 20, 2025
Published to the GitHub Advisory Database
Mar 20, 2025
Last updated
Mar 20, 2025
A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is present in the
POST /v1/llm/add_llm
andPOST /v1/conversation/tts
endpoints. Attackers can specify an arbitrary URL as theapi_base
when adding anOPENAITTS
model, and subsequently access thetts
REST API endpoint to read contents from the specified URL. This can lead to unauthorized access to internal web resources.References