mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only from the configuration file but also from other inputs, allowing an attacker to upload a binary file and execute malicious code. This can lead to the attacker gaining full control over the system.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HMudler Localai
APPMudler2.17.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2024-6868CRITICAL9.8PL ✓same product
Podatność tarslip w LocalAI umożliwiająca RCE przez arbitralny zapis pliku
CVE-2024-5181CRITICAL9.8PL ✓same product
Command injection w LocalAI — pełne przejęcie systemu przez parametr backend
CVE-2024-5182CRITICAL9.1PL ✓same product
Path traversal w LocalAI umożliwiający usuwanie dowolnych plików
CVE-2024-2029CRITICAL9.8PL ✓same product
Command injection w mudler/LocalAI — endpoint transkrypcji audio
CVE-2024-9900MEDIUM6.1same product
mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality...