CVE-2024-9309

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
20/03/2025
Last modified:
15/07/2025

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-liu/llava version v1.2.0 (LLaVA-1.6). This vulnerability allows attackers to exploit the victim Controller API Server's credentials to perform unauthorized web actions or access unauthorized web resources.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hliu:llava:1.2.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools