CVE-2026-86539 UNKNOWN

CVE-2026-86539

Published: 2026-09-07

Description

knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…