Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9c54-gxh7-ppjc | Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 23 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Dec 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (download_service.py) makes HTTP requests using raw requests.get() without utilizing the application's SSRF protection (safe_requests.py). This can allow attackers to access internal services and attempt to reach cloud provider metadata endpoints (AWS/GCP/Azure), as well as perform internal network reconnaissance, by submitting malicious URLs through the API, depending on the deployment and surrounding controls. This issue has been patched in version 1.3.9. | |
| Title | Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-23T15:41:01.533Z
Reserved: 2025-12-11T18:08:02.946Z
Link: CVE-2025-67743
Updated: 2025-12-23T15:40:42.575Z
Status : Awaiting Analysis
Published: 2025-12-23T01:15:43.160
Modified: 2025-12-23T16:16:23.337
Link: CVE-2025-67743
No data.
OpenCVE Enrichment
No data.
Github GHSA