CVE-2025-61784Disclosure(hiyouga / llama-factory)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat API allows any authenticated user to force the server to make arbitrary HTTP requests to internal and external networks. This can lead to the exposure of sensitive internal services, reconnaissance of the internal network, or interaction with third-party services. The same mechanism also allows for a Local File Inclusion (LFI) vulnerability, enabling users to read arbitrary files from the server's filesystem. The vulnerability exists in the `_process_request` function within `src/llamafactory/api/chat.py.` This function is responsible for processing incoming multimodal content, including images, videos, and audio provided via URLs. The function checks if the provided URL is a base64 data URI or a local file path (`os.path.isfile`). If neither is true, it falls back to treating the URL as a web URI and makes a direct HTTP GET request using `requests.get(url, stream=True).raw` without any validation or sanitization of the URL. Version 0.9.4 fixes the underlying issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • llama-factory

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
llama-factory

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-20: 1Technical Details · 2026-03-20: 103-20
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • PulsePatch.io@pulsepatchio
    Disclosure

    Critical SSRF & LFI flaws in `LLaMA Factory` Chat API (CVE-2025-61784) pose data exfiltration risks. Review API exposure and internal network segmentation. #infosec #vulnerability https://www.pulsepatch.io/posts/cve-2025-61784-llama-factory-chat-api-ssrf-lfi

    Post summary

    The post announces a critical SSRF and LFI vulnerability (CVE‑2025‑61784) in LLaMA Factory Chat API that could allow data exfiltration, but no PoC, exploit, or patch information is provided.

    0000093
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphiyougallama-factory---

Explore more