CVE-2026-73560: vLLM: SSRF/LFI bypass in MiMo-V2 multimodal input
GHSA-4hhp-h66f-j5j7 MEDIUM CISA: TRACK*A flaw in vLLM's multimodal processor for the MiMo-V2-Omni model lets attacker-supplied image and audio URLs bypass the platform's own SSRF and local-file-read protections, sending the request straight to requests.get and Image.open instead of the sanitized MediaConnector path. Any deployment that relies on allowed_media_domains or allowed_local_media_path to fence off internal networks or the local filesystem is effectively unprotected when this model processor is in use. There's no CISA KEV listing, no public exploit or Nuclei template, and no EPSS score published yet, so this looks like a disclosed-not-exploited bug rather than an active campaign — but vLLM is one of the most widely deployed inference engines, and cloud metadata endpoints (e.g. AWS IMDS) and local secrets are the obvious targets for this class of bug. Upgrade to vLLM 0.26.0 immediately for any deployment serving multimodal models; until then, restrict egress from inference hosts to internal/metadata IP ranges and audit which models with image/audio inputs are exposed to untrusted callers.
What is the risk?
Network-exploitable with low attack complexity and no user interaction, but requires low privileges (authenticated API access to the inference endpoint), which narrows the exposure to environments where the vLLM multimodal endpoint is reachable by semi-trusted or external tenants. Impact is confidentiality-only (C:H/I:N/A:N) — no integrity or availability effect — but the confidentiality loss can be severe: SSRF to cloud metadata services can yield IAM credentials, and arbitrary local file reads can expose API keys, model configs, or other secrets accessible to the vLLM process. No KEV listing, no EPSS data, and no known public exploit or scanner template exist yet, so near-term mass exploitation is unlikely, but the bug is trivial to weaponize once the affected model/processor combination is identified in a target's stack.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| vLLM | pip | < 0.26.0 | 0.26.0 |
Do you use vLLM? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Upgrade vLLM to 0.26.0 or later, which fixes the processor to route media through MediaConnector as intended. If immediate upgrade isn't possible, disable or avoid exposing the MiMo-V2-Omni multimodal processor to untrusted input, and add network-level egress controls on inference hosts blocking outbound requests to link-local/metadata ranges (169.254.169.254, internal RFC1918 ranges) and to the local filesystem via file:// schemes. Run the vLLM process with a restricted filesystem view (container/chroot, minimal mount surface, no cloud credential files reachable) as defense in depth. Monitor inference server logs for outbound requests.get/Image.open calls targeting internal IPs or unexpected file paths, and review the GitHub Security Advisory (GHSA-4hhp-h66f-j5j7) for IOCs.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-73560?
A flaw in vLLM's multimodal processor for the MiMo-V2-Omni model lets attacker-supplied image and audio URLs bypass the platform's own SSRF and local-file-read protections, sending the request straight to requests.get and Image.open instead of the sanitized MediaConnector path. Any deployment that relies on allowed_media_domains or allowed_local_media_path to fence off internal networks or the local filesystem is effectively unprotected when this model processor is in use. There's no CISA KEV listing, no public exploit or Nuclei template, and no EPSS score published yet, so this looks like a disclosed-not-exploited bug rather than an active campaign — but vLLM is one of the most widely deployed inference engines, and cloud metadata endpoints (e.g. AWS IMDS) and local secrets are the obvious targets for this class of bug. Upgrade to vLLM 0.26.0 immediately for any deployment serving multimodal models; until then, restrict egress from inference hosts to internal/metadata IP ranges and audit which models with image/audio inputs are exposed to untrusted callers.
Is CVE-2026-73560 actively exploited?
No confirmed active exploitation of CVE-2026-73560 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-73560?
Upgrade vLLM to 0.26.0 or later, which fixes the processor to route media through MediaConnector as intended. If immediate upgrade isn't possible, disable or avoid exposing the MiMo-V2-Omni multimodal processor to untrusted input, and add network-level egress controls on inference hosts blocking outbound requests to link-local/metadata ranges (169.254.169.254, internal RFC1918 ranges) and to the local filesystem via file:// schemes. Run the vLLM process with a restricted filesystem view (container/chroot, minimal mount surface, no cloud credential files reachable) as defense in depth. Monitor inference server logs for outbound requests.get/Image.open calls targeting internal IPs or unexpected file paths, and review the GitHub Security Advisory (GHSA-4hhp-h66f-j5j7) for IOCs.
What systems are affected by CVE-2026-73560?
This vulnerability affects the following AI/ML architecture patterns: model serving, multimodal inference pipelines, cloud-hosted inference APIs.
What is the CVSS score for CVE-2026-73560?
CVE-2026-73560 has a CVSS v3.1 base score of 6.5 (MEDIUM). The EPSS exploitation probability is 0.41%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0025 Exfiltration via Cyber Means AML.T0040 AI Model Inference API Access AML.T0049 Exploit Public-Facing Application Compliance Controls Affected
What are the technical details?
Original Advisory
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through _fetch_image, requests.get, and Image.open instead of MediaConnector, bypassing allowed_media_domains and allowed_local_media_path protections and allowing server-side requests and reads of arbitrary files accessible to the vLLM process. This issue is fixed in version 0.26.0.
Exploitation Scenario
An attacker with legitimate but low-privilege API access to a vLLM deployment serving the MiMo-V2-Omni model submits an inference request whose image or audio field is a URL pointing at the cloud provider's metadata service (e.g. http://169.254.169.254/latest/meta-data/iam/security-credentials/) or a local file path (file:///etc/passwd, or a mounted secrets file). Because the MiMoV2OmniMultiModalProcessor hands this value directly to requests.get or Image.open instead of the sanitized MediaConnector, the allowlist checks never fire, the vLLM process fetches or reads the target on the attacker's behalf, and the resulting content — potentially including temporary cloud credentials or application secrets — is returned or reflected back through the model's processing path to the attacker.
Weaknesses (CWE)
CWE-918 Server-Side Request Forgery (SSRF)
Primary
CWE-918 Server-Side Request Forgery (SSRF)
Primary
CWE-918 Server-Side Request Forgery (SSRF) CWE-918 — Server-Side Request Forgery (SSRF): The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N References
- github.com/advisories/GHSA-4hhp-h66f-j5j7
- nvd.nist.gov/vuln/detail/CVE-2026-73560
- github.com/vllm-project/vllm/commit/54503ecec0f3ac31e5ecfc5f28652e4cc42307b5
- github.com/vllm-project/vllm/pull/43117
- github.com/vllm-project/vllm/releases/tag/v0.26.0
- github.com/vllm-project/vllm/security/advisories/GHSA-4hhp-h66f-j5j7
Timeline
Related Vulnerabilities
CVE-2026-61732 10.0 Analysis pending
Same package: vllm CVE-2026-25960 9.8 vllm: SSRF allows internal network access
Same package: vllm CVE-2024-11041 9.8 vllm: RCE via unsafe pickle deserialization in MessageQueue
Same package: vllm CVE-2025-47277 9.8 vLLM: RCE via exposed TCPStore in distributed inference
Same package: vllm CVE-2024-9053 9.8 vllm: RCE via unsafe pickle deserialization in RPC server
Same package: vllm