knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-07 23:16
Updated : 2026-09-09 15:17
NVD link : CVE-2026-86539
Mitre link : CVE-2026-86539
CVE.ORG link : CVE-2026-86539
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
