Vendorsmudlerlocalaiany version
Vulnerabilities

mudler LocalAI any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2024-2029
Command Injection in mudler/localai
Published 2024-04-10 · Analyzed
9.8EPSS 0.029
CVE-2024-5182
Path Traversal in mudler/localai
Published 2024-06-19 · Modified
9.1EPSS 0.255
CVE-2024-3135
Cross-Site Request Forgery (CSRF) Vulnerability in mudler/localai
Published 2024-04-01 · Analyzed
6.5EPSS 0.003
CVE-2024-48057
localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage XSS, which will trigger the payload when a user accesses the homepage.
Published 2024-11-04 · Analyzed
6.1EPSS 0.002
CVE-2024-6095
SSRF and Partial LFI in /models/apply Endpoint in mudler/localai
Published 2024-07-06 · Modified
5.8EPSS 0.027
CVE-2024-5616
CSRF Vulnerability in mudler/LocalAI
Published 2024-07-06 · Analyzed
4.3EPSS 0.003