๐Ÿ” CVE Alert

CVE-2026-108719

MEDIUM 5.0

LLMGateway through 1.20.0 Blind SSRF via Video-Generation callback_url

CVSS Score
5.0
EPSS Score
0.0%
EPSS Percentile
0th

LLMGateway through 1.20.0 contains a blind server-side request forgery vulnerability that allows API key holders to reach internal hosts via the video-generation callback_url extension. Attackers can supply loopback, private, or cloud-metadata URLs that deliverWebhook POSTs to without the assertSafeWebhookTarget check, reaching internal services from the worker's network.

CWE CWE-918
Vendor theopenco
Product llmgateway
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for theopenco llmgateway

Be the first to know when new medium vulnerabilities affecting theopenco llmgateway are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

theopenco / LLMGateway
0 โ‰ค 1.20.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind03/theopenco-llmgateway-video-callback-ssrf-no-egress-guard github.com: https://github.com/theopenco/llmgateway/blob/c84ba987da18edd80358a3450ccaea75c5c67ca8/apps/gateway/src/videos/videos.ts#L374-L383 github.com: https://github.com/theopenco/llmgateway/blob/c84ba987da18edd80358a3450ccaea75c5c67ca8/apps/worker/src/services/video-jobs.ts#L2490-L2499 github.com: https://github.com/theopenco/llmgateway/blob/c84ba987da18edd80358a3450ccaea75c5c67ca8/apps/worker/src/worker.ts#L2961-L2971 github.com: https://github.com/theopenco/llmgateway vulncheck.com: https://www.vulncheck.com/advisories/llmgateway-through-1.20.0-blind-ssrf-via-video-generation-callback-url

Credits

HaiND from the Post and Telecommunication Institute of Technology