YAML Metadata Warning:empty or missing yaml metadata in repo card
Check out the documentation for more information.
PoC: Blind SSRF in llama.cpp Server
Description
A Server-Side Request Forgery (SSRF) exists in the multimodal image fetching logic of llama-server. An attacker can force the server to make outbound HTTP requests to internal resources or cloud metadata endpoints.
Reproduction Steps
- Start listener:
python3 -m http.server 9000 - Run server:
./bin/llama-server -m qwen2-vl-2b-q4_k.gguf --mmproj mmproj-qwen2-vl-2b.gguf - Execute PoC:
bash poc_exploit.sh
Impact
High/Critical. Bypasses network firewalls and allows exfiltration of AWS/GCP/Azure instance metadata credentials (IMDS).
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support