{"id":"CVE-2026-70620","published":"2026-08-04T22:17:17.727","lastModified":"2026-08-05T15:17:16.810","description":"Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint configuration without scheme, host, IP range, or DNS rebind validation. Attackers can submit loopback addresses, RFC 1918 ranges, or link-local addresses through the embedding endpoint API to partially read responses from cloud instance metadata services, internal APIs, and other hosts reachable from the server.","cvssScore":6.8,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","cwes":["CWE-918"],"vendors":[],"products":[],"references":[{"url":"https://aydinnyunus.github.io/2026/06/16/odysseus-embedding-endpoint-takeover/","tags":[]},{"url":"https://github.com/odysseus-dev/odysseus/commit/87babb58d57897089b133b313e2ab6d09e7ef54e","tags":[]},{"url":"https://github.com/odysseus-dev/odysseus/issues/132","tags":[]},{"url":"https://github.com/odysseus-dev/odysseus/pull/1206","tags":[]},{"url":"https://www.vulncheck.com/advisories/odysseus-ssrf-via-embedding-endpoint-configuration","tags":[]}],"exploitRefs":[{"url":"https://github.com/odysseus-dev/odysseus/commit/87babb58d57897089b133b313e2ab6d09e7ef54e","tags":[]},{"url":"https://github.com/odysseus-dev/odysseus/issues/132","tags":[]},{"url":"https://github.com/odysseus-dev/odysseus/pull/1206","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows admin-privileged attackers to probe internal network resources by submitting arbitrary URLs without proper validation, potentially reading sensitive information from cloud metadata services and internal APIs.","exploitability":"Exploitation requires admin privileges and knowledge of loopback addresses or RFC 1918 ranges; moderate difficulty due to the need for specific URL crafting.","blast_radius":"If exploited, this could lead to unauthorized access to sensitive internal resources, compromising data security within the network.","remediation":"Implement strict validation checks on URLs submitted through the embedding endpoint API to prevent server-side request forgery attacks.","tags":["ssrf","internal-probe","validation","api-security"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:04:25.947Z"}}