Impact
The vulnerability is a blind server‑side request forgery that allows API key holders to supply a callback URL during video generation. The code path that delivers the webhook response lacks proper target validation, so an attacker can specify loopback, private‑IP, or cloud‑metadata URLs. The worker process sends the request from its network, enabling the attacker to reach internal services exposed to that network.
Affected Systems
Theopenco’s LLMGateway distributed through version 1.20.0 is affected. No other vendors or product variants have been reported as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not provided, meaning no publicly available estimate of exploitation probability exists. The vulnerability is not listed in CISA KEV. The attack requires a valid API key, and the effect is confined to internal network hosts that the worker can contact. An attacker can probe or manipulate services reachable from the worker’s network, but the flaw does not grant remote code execution or direct external data exfiltration.
OpenCVE Enrichment