MEDIUM
theopenco
CVE published 2026-10-11
CVE-2026-108719
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-11T12:19:30.605Z and has not been modified since then. LLMGateway through 1.20.0 contains a blind server-side request forgery vulnerability that allows API key holders to reach internal hosts via the video-generation callback_url extension. Attackers can supply loopback, private, or cloud-metadata U [truncated]