« Volver al listado

Mudler

Mudler Localai: vulnerabilidades y CVE

Mudler Localai tiene 12 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses1
Críticas5
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-59707Crítica (9.2)0.48%—7 jul 2026
LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized gallery URL fields…
CVE-2024-9900Media (6.1)0.54%—20 mar 2025
mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vulnerability arises due to improper sanitization of user input, allowing the injection and execution…
CVE-2024-48057Media (6.1)0.24%—4 nov 2024
localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage XSS, which will trigger the payload when a user…
CVE-2024-7010Media (5.9)0.52%—29 oct 2024
mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms.…
CVE-2024-6868Crítica (9.8)1.5%—29 oct 2024
mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. When model configurations specify additional files as archives (e.g., .tar), these archives are…
CVE-2024-6983Alta (8.8)1.3%—27 sept 2024
mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only from the configuration file but also from other inputs, allowing an…
CVE-2024-6095Media (5.8)2.6%—6 jul 2024
A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server-Side Request Forgery (SSRF) and partial Local File Inclusion (LFI). The endpoint supports both http(s):// and file://…
CVE-2024-5616Media (4.3)0.25%—6 jul 2024
A Cross-Site Request Forgery (CSRF) vulnerability exists in mudler/LocalAI versions up to and including 2.15.0, which allows attackers to trick victims into deleting installed models. By crafting a malicious HTML page,…
CVE-2024-5181Crítica (9.8)2.7%—26 jun 2024
A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backend parameter in the configuration file, which is used in the name of…
CVE-2024-5182Crítica (9.1)26%—20 jun 2024
A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion process to delete arbitrary files. Specifically, by crafting a…
CVE-2024-2029Crítica (9.8)2.9%—10 abr 2024
A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioToWav` function used for converting audio files to WAV format for transcription. The vulnerability…
CVE-2024-3135Media (6.5)0.31%—1 abr 2024
A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when visited by a victim, perform unauthorized actions on the victim's…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1090 Proxy1
  2. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.