CVE-2026-86539
EUVD-2026-7255707.09.2026, 23:16
knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References