Impact
Marqo version 2.26.0 contains a server‑side request forgery vulnerability in the add_documents endpoint. By supplying malicious media field values, an unauthenticated attacker can cause the application to perform HTTP requests to arbitrary URLs. The flaw arises because download_image_from_url and fetch_content_sample functions do not perform destination filtering or host validation, enabling attackers to access internal services and cloud metadata endpoints, which could lead to information disclosure or further compromise.
Affected Systems
The affected product is Marqo by marqo‑ai. Only the 2.26.0 release is impacted; no other versions or build‑variants are mentioned.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of exploitation in the wild. Nevertheless, the attack vector is remote and requires no authentication, meaning any external or exposed user interface could be abused. Exploitation would allow attackers to reach internal network resources, potentially exposing sensitive data.
OpenCVE Enrichment