CVE-2025-67743 Overview
CVE-2025-67743 is a Server-Side Request Forgery (SSRF) vulnerability affecting Local Deep Research, an AI-powered research assistant for iterative research workflows. The flaw exists in the download_service.py component, which issues HTTP requests using raw requests.get() calls while bypassing the application's existing SSRF protection in safe_requests.py. Authenticated attackers can submit malicious URLs through the API to probe internal services, reach cloud provider metadata endpoints on AWS, GCP, and Azure, and conduct internal network reconnaissance. The issue affects versions from 1.3.0 to before 1.3.9 and is tracked under [CWE-918].
Critical Impact
Authenticated attackers can abuse the download service to pivot into internal networks and attempt to retrieve cloud instance metadata containing credentials and configuration secrets.
Affected Products
- Learningcircuit Local Deep Research versions 1.3.0 through 1.3.8
- Deployments exposing the download API to untrusted users
- Cloud-hosted instances on AWS, GCP, or Azure with accessible metadata endpoints
Discovery Timeline
- 2025-12-23 - CVE CVE-2025-67743 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-67743
Vulnerability Analysis
Local Deep Research implements an SSRF protection layer in safe_requests.py intended to validate outbound HTTP destinations before issuing requests. The download service bypasses this control by invoking requests.get() directly, allowing arbitrary URLs supplied through the API to reach any network-reachable host. An authenticated user can submit URLs targeting loopback interfaces, RFC1918 ranges, or cloud metadata services such as http://169.254.169.254/.
Successful exploitation enables internal service enumeration, retrieval of cloud instance metadata, and potential exposure of temporary IAM credentials in cloud deployments. The impact scope depends on surrounding network controls, IMDS version configuration, and whether the application runs with workload identities attached.
Root Cause
The root cause is inconsistent enforcement of outbound request filtering. The application ships a dedicated SSRF-safe HTTP wrapper, but the download service imports the standard requests library and calls it directly. This design gap means URL validation, scheme restrictions, and private-IP blocking never execute for download requests.
Attack Vector
An authenticated attacker sends a crafted request to the download API endpoint, supplying a URL that points to an internal resource. The server retrieves the URL on behalf of the attacker and returns or processes the response, exposing internal content. No user interaction is required beyond providing valid API credentials.
# Patch excerpt: src/local_deep_research/api/client.py
-import requests
import time
from typing import Optional, Dict, Any, List
from loguru import logger
from local_deep_research.benchmarks.comparison.results import Benchmark_results
+from local_deep_research.security import SafeSession
class LDRClient:
# Patch excerpt: src/local_deep_research/config/llm_config.py
from ..llm import get_llm_from_registry, is_llm_registered
from ..utilities.search_utilities import remove_think_tags
from ..utilities.url_utils import normalize_url
+from ..security import safe_get
Source: GitHub commit b79089f
Detection Methods for CVE-2025-67743
Indicators of Compromise
- Outbound HTTP requests from the Local Deep Research host to RFC1918 ranges, loopback addresses, or 169.254.169.254
- API request logs containing download URLs pointing to internal hostnames or metadata endpoints
- Unexpected access patterns to AWS IMDS, GCP metadata.google.internal, or Azure IMDS from the application workload
Detection Strategies
- Inspect application logs for calls to the download service with URLs containing private IP ranges, link-local addresses, or non-HTTPS schemes
- Correlate authenticated API session identifiers with anomalous outbound destinations recorded by the host or network layer
- Alert on any download service request returning cloud metadata JSON structures or STS credential patterns
Monitoring Recommendations
- Enable VPC flow logs and egress monitoring on hosts running Local Deep Research to capture connections to internal subnets
- Enforce IMDSv2 on AWS workloads and monitor failed IMDSv1 token-less requests as a signal of SSRF probing
- Baseline normal outbound destinations for the application and alert on deviations
How to Mitigate CVE-2025-67743
Immediate Actions Required
- Upgrade Local Deep Research to version 1.3.9 or later, which routes download requests through the SSRF-safe SafeSession and safe_get helpers
- Restrict API access to trusted authenticated users and apply rate limiting on the download endpoint
- Enforce IMDSv2 and remove unnecessary IAM permissions from workload identities attached to the application
Patch Information
The fix is published in version 1.3.9 and committed as b79089ff30c5d9ae77e6b903c408e1c26ad5c055. The patch removes direct requests imports from the download service and client modules, replacing them with the SafeSession and safe_get wrappers from local_deep_research.security. See the GitHub Security Advisory GHSA-9c54-gxh7-ppjc for the full advisory.
Workarounds
- Place the application behind an egress proxy that blocks requests to private IP ranges and cloud metadata endpoints
- Deploy the service in a network segment with no route to internal services or metadata IPs
- Disable or firewall the download endpoint until the upgrade to 1.3.9 is applied
# Upgrade Local Deep Research to the patched release
pip install --upgrade "local-deep-research>=1.3.9"
# AWS: enforce IMDSv2 on the instance to reduce SSRF impact
aws ec2 modify-instance-metadata-options \
--instance-id i-0123456789abcdef0 \
--http-tokens required \
--http-endpoint enabled
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.