THREAT OPS › Threat News › [GHSA] GHSA-m3wp-48jr-vr4g (high) — mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
[GHSA] GHSA-m3wp-48jr-vr4g (high) — mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
GHSA-m3wp-48jr-vr4g Severity: high CVE: None
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
## Unbounded Remote Media Fetch and Video Frame Expansion DoS
### Summary The `POST /v1/chat/completions` endpoint in mistral.rs fetches attacker-supplied media URLs (image, audio, video) into server memory with no byte limit, and extracts every frame of a supplied video when `nu
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- http://127.0.0.1:8000/v1/chat/completionsurl
- http://ATTACKER:9001/many_frames.mp4url
- http://ATTACKER:9002/bloburl
- http://{MALICIOUS_HOST}:{MALICIOUS_PORT}/infiniteurl
Original source: https://github.com/advisories/GHSA-m3wp-48jr-vr4g