We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-5616

CSRF Vulnerability in mudler/LocalAI



Assigner@huntr_ai
Reserved2024-06-04
Published2024-07-06
Updated2024-08-01

Description

A Cross-Site Request Forgery (CSRF) vulnerability exists in mudler/LocalAI versions up to and including 2.15.0, which allows attackers to trick victims into deleting installed models. By crafting a malicious HTML page, an attacker can cause the deletion of a model, such as 'gpt-4-vision-preview', without the victim's consent. The vulnerability is due to insufficient CSRF protection mechanisms on the model deletion functionality.



MEDIUM: 4.3CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Problem types

CWE-352 Cross-Site Request Forgery (CSRF)

Product status

Any version before 2.17
affected

References

https://huntr.com/bounties/fd753fb6-ba04-4dd8-abef-918fb97120af

https://github.com/mudler/localai/commit/4e1463fec291612a59a16db60b3fd12d4c49d64b

cve.org CVE-2024-5616

nvd.nist.gov CVE-2024-5616

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.