Impact
Helicone ai‑gateway includes a function that constructs URLs from an extracted path and query string without proper validation, allowing an attacker to forge requests to arbitrary internal or external endpoints. By manipulating the extracted argument the attacker can cause the gateway to send HTTP requests to internal services, notably the AWS Metadata Service, resulting in the disclosure of sensitive data or execution of unintended actions. This flaw belongs to the input validation weakness category (CWE‑918) and enables a remote attacker to trigger unintended outbound traffic from the vulnerable component.
Affected Systems
The vulnerability exists in Helicone ai‑gateway versions up to 0.2 at risk; the flaw is triggered by the AWS Metadata Service implementation within the dispatcher’s service module.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. < 1% indicates a very low probability of exploitation, but the exploit has The flaw is exploitable remotely, and the supplier has not yet provided a patch. The vulnerability is not listed in CISA KEV, yet its public availability and potential to reach internal services make it a notable risk.
OpenCVE Enrichment