Unrated severityOSV Advisory· Published Sep 6, 2026
OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation
CVE-2026-86259
Description
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.
Affected products
1- Range: @openmaic/[email protected], @openmaic/[email protected], @openmaic/[email protected], …
Patches
Vulnerability mechanics
References
5- github.com/THU-MAIC/OpenMAIC/releases/tag/v1.0.1mitrepatchrelease-notes
- github.com/THU-MAIC/OpenMAIC/security/advisories/GHSA-9m7h-vh2h-rc3wmitrevendor-advisory
- www.vulncheck.com/advisories/openmaic-before-1.0.1-ssrf-via-environment-gated-url-validationmitrethird-party-advisory
- github.com/THU-MAIC/OpenMAIC/blob/v1.0.0/app/api/generate/image/route.tsmitretechnical-description
- github.com/THU-MAIC/OpenMAIC/blob/v1.0.0/middleware.tsmitretechnical-description
News mentions
0No linked articles in our index yet.