// vLLM / case study

Multimodal media path bypassed hardened retrieval controls

A model-specific processor fetched user-controlled image and audio references outside vLLM's hardened MediaConnector path, reintroducing SSRF and local-file access.

Published | CVE-2026-73560 | Moderate 6.5Disclosure-safe summary
Trust-boundary path
01User-controlled media reference
02Model-specific processor
03Internal network or local files

Project and affected component

Multimodal image and audio loading in the MiMoV2Omni processor.

Security boundary

Untrusted media references should pass through the same centralized network and local-file security policy regardless of which model-specific processing path receives them.

Vulnerability class

Server-side request forgery and unauthorized local-file access caused by incomplete coverage of an existing security control.

Root cause

The model-specific processor performed network requests and local-file opens directly instead of routing the inputs through vLLM's hardened MediaConnector. The central connector already enforced security policy for other media-loading paths, but this later processor bypassed that boundary.

Validation method

Source review compared the model-specific processor with the previously hardened media-loading path. Controlled network and local-file cases reproduced the bypass, and matched controls confirmed that the centralized MediaConnector path enforced the intended policy.

Practical impact

A user able to supply multimodal input to the affected path could cause the vLLM process to reach internal network destinations or access local files available to the serving process.

Disclosure status

vLLM published GHSA-4hhp-h66f-j5j7 and CVE-2026-73560. The issue was fixed in vLLM 0.26.0. GitHub lists ibondarenko1 as the reporter.

Remediation

Route every model-specific media-loading path through the same centralized connector and security policy. Avoid direct network requests or unrestricted local-file access inside model processors, and add regression coverage for new processors.

Public references