Downloads · 30 days
0
anandppatil4383/llama-cpp-ssrf-poc
llama-cpp-ssrf-poc is a machine learning model from anandppatil4383. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
A Server-Side Request Forgery (SSRF) exists in the multimodal image fetching logic of llama-server. An attacker can force the server to make outbound HTTP requests to internal resources or cloud metadata endpoints.
Downloads · 30 days
0
Access
Public
Updated Feb 4, 2026
Repo size
136 MB
Likes
0
Public
Click a slice to open those files.
.mp4136 MB · 100%
From the Hugging Face model README
A Server-Side Request Forgery (SSRF) exists in the multimodal image fetching logic of llama-server. An attacker can force the server to make outbound HTTP requests to internal resources or cloud metadata endpoints.
python3 -m http.server 9000./bin/llama-server -m qwen2-vl-2b-q4_k.gguf --mmproj mmproj-qwen2-vl-2b.ggufbash poc_exploit.shHigh/Critical. Bypasses network firewalls and allows exfiltration of AWS/GCP/Azure instance metadata credentials (IMDS).