Vulnerabilities
Vulnerable Software
Hliu:  >> Llava  >> 1.2.0  Security Vulnerabilities
An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.
CVSS Score
6.1
EPSS Score
0.001
Published
2025-03-20
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-liu/llava version v1.2.0 (LLaVA-1.6). This vulnerability allows attackers to exploit the victim Controller API Server's credentials to perform unauthorized web actions or access unauthorized web resources.
CVSS Score
9.3
EPSS Score
0.001
Published
2025-03-20
A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the end of a multipart boundary in a file upload request. This causes the server to continuously process each character, rendering the application inaccessible.
CVSS Score
7.5
EPSS Score
0.002
Published
2025-03-20


Contact Us

Shodan ® - All rights reserved