THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-4hhp-h66f-j5j7 (medium) — vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

[GHSA] GHSA-4hhp-h66f-j5j7 (medium) — vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

highgithub_advisoriesPublished 2026-09-08

GHSA-4hhp-h66f-j5j7 Severity: medium CVE: CVE-2026-73560

vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections

### Summary

`vllm/transformers_utils/processors/mimo_v2_omni.py` — the multimodal processor for `MiMoV2OmniForCausalLM` — issues `requests.get(...)` directly on user-supplied image and audio URL strings

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-4hhp-h66f-j5j7