CyberRota Analysis
AI-GeneratedThe vulnerability in Jina AI Reader allows unauthenticated attackers to exploit server-side request forgery by disabling the private-address guard in non-Google Cloud environments. This flaw enables attackers to access sensitive cloud metadata and internal service content by supplying publicly resolvable hostnames that map to private addresses. Organizations using Jina AI Reader outside of Google Cloud should prioritize addressing this issue to mitigate potential data exposure risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retrieve cloud metadata and internal service content.