Impact
A flaw in the guardrails-detectors component allows a remote attacker to submit a crafted XML Schema Definition that triggers blind Server-Side Request Forgery, enabling the attacker to access sensitive information such as cloud metadata services, the Kubernetes API, internal MinIO, and other internal network endpoints, and to read local files on the node, including service-account tokens and pod secrets.
Affected Systems
Red Hat OpenShift AI contains the vulnerable guardrails-detectors component; any deployment that includes this component may be affected, though no specific version range is listed.
Risk and Exploitability
The vulnerability has a CVSS score of 9.3, indicating very high severity, while the EPSS score is reported as less than 1%, suggesting a low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. The attack vector is inferred to be a remote delivery of a malicious XML schema to the guardrails-detectors endpoint, which causes the component to fetch and process external resources, enabling blind SSRF and local file reads. An attacker with network access to the component can reach internal services or read sensitive files on the node.
OpenCVE Enrichment