CVE-2026-85673: LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL han | AI Sec Watch