#10646·LlamaFactory通过 API 服务器中的 image_url 进行未授权的 SSRF 攻击,通过重定向和 DNS 重绑定绕过 check_ssrf_url(修复不完整)作者: geo-chen创建于 2026年7月13日更新于 2026年9月4日标签bugpending提醒信息 内容来源: hiyouga/LlamaFactory查看 GitHub 原文在 GitHub 查看讨论