CyberRota Analysis
AI-GeneratedThe ms-swift 4.5.2 version is vulnerable to a server-side request forgery (SSRF) that allows unauthenticated attackers to exploit the OpenAI-compatible API by supplying arbitrary media URL parameters. This can lead to unauthorized access to internal services and cloud metadata, potentially exposing sensitive information. Organizations using this version should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redirect filtering. Unauthenticated attackers can supply arbitrary image_url, audio_url, or video_url parameters to make the server issue requests to internal services and cloud metadata endpoints.