VYPR

llmgateway

by Theopenco

CVEs (1)

  • CVE-2026-108719MedOct 11, 2026
    risk 0.26cvss 5.0epss —

    LLMGateway through 1.20.0 contains a blind server-side request forgery vulnerability that allows API key holders to reach internal hosts via the video-generation callback_url extension. Attackers can supply loopback, private, or cloud-metadata URLs that deliverWebhook POSTs to…