THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wfgq-w7cq-qj7j (high) — mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

[GHSA] GHSA-wfgq-w7cq-qj7j (high) — mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

highgithub_advisoriesPublished 2026-09-10

GHSA-wfgq-w7cq-qj7j Severity: high CVE: None

mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

### Summary mistral.rs fetches any request-supplied image/audio URL with no host or IP validation, and opens arbitrary local files (a `file://` URL, or any existing relative/absolute path). A remote, unauthenticated client of any vision/audio deployment can cause

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wfgq-w7cq-qj7j