CVE-2024-9309 | haotian-liu llava up to 1.2.0/1.6 API Endpoint /worker_generate_stream server-side request forgery
A vulnerability was found in haotian-liu llava up to 1.2.0/1.6. It has been classified as critical. Affected is an unknown function of the file /worker_generate_stream of the component API Endpoint. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2024-9309. It is possible to launch the attack remotely. There is no exploit available.