Impact
A Server‑Side Request Forgery (SSRF) flaw exists in the swift deploy API of ms‑swift 4.5.2. The API accepts multipart image, audio, and video URLs without validating them or filtering redirects. Consequently, an unauthenticated attacker can instruct the server to fetch arbitrary resources, potentially exposing internal services or cloud metadata endpoints. The weakness is a classic CWE‑918 scenario where external input is not properly sandboxed.
Affected Systems
The vulnerability affects the modelScope ms‑swift package, version 4.5.2. No other versions or vendor products are listed as impacted in the advisory.
Risk and Exploitability
With a CVSS score of 8.7, this issue is considered a high‑severity vulnerability. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, though the lack of authentication could still make it attractive to attackers. Because the vector requires only unauthenticated remote calls to the API, exploitation can be achieved from any external network without credentials, allowing attackers to probe internal infrastructure.
OpenCVE Enrichment