CVE-2026-85673 | hiyouga LLaMA-Factory up to 0.9.5 OpenAI-compatible API Multimodal Media URL requests.get server-side request forgery

SecurityVulns

A vulnerability identified as problematic has been detected in hiyouga LLaMA-Factory up to 0.9.5. This vulnerability affects the function requests.get of the component OpenAI-compatible API Multimodal Media URL Handler. Performing a manipulation results in server-side request forgery.

This vulnerability is identified as CVE-2026-85673. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More