The SSRF vulnerability resides within LMDeploy's vision-language module, specifically in the load_image() function, which fails to validate internal or private IP addresses when fetching URLs.
Attacks weaponizing the Cisco Adaptive Security Appliance vulnerabilities, tracked as CVE-2025-20333 and CVE-2025-20362, were reported by the Cybersecurity and Infrastructure Security Agency to have successfully compromised a federal civilian executive branch agency with the FIRESTARTER malware in September, according to The Record, a news site by cybersecurity firm Recorded Future.
The vulnerability, with a critical severity score of 9.8 out of 10, stems from a missing file-type validation in the "fetch_gravatar_from_remote" function.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.