Tools AI-Found Vulnerability Register aifv-0036
Register entry
LLaVA server-side request forgery at POST /worker_generate_stream, found by Vulnhuntr
- CVE
- CVE-2024-9309
- Project
- haotian-liu/LLaVA
- Finder
- Vulnhuntr
- Autonomy
- LLM with Jedi static parsing, Python only; findings routed through huntr
- Evidence tier
- Claim outside the record
- Assigner
- @huntr_ai
- Severity
- 9.3 Critical (CVSS 3.1)
- Bounty
- huntr.com; amount unpublished
- Confidence
- CONFIRMED
What happened
A server-side request forgery at POST /worker_generate_stream in haotian-liu/LLaVA, assigned by huntr with an empty credits array, listed in the Vulnhuntr README under "World's first autonomous AI-discovered 0day vulnerabilities". Product, class, date and CVSS reproduce at the record; the affected version numbers in circulation trace to huntr pages this desk has not opened.
Credit as recorded: credits array empty; attribution in the Vulnhuntr README. Date basis: datePublished.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
- Vulnhuntr READMEraw.githubusercontent.com/protectai/vulnhuntr/main/README.md
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026