Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Localai MEDIUM 6.1
CVE-2024-9900

mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vulnerability arises due to impro…

Patch available
Fix from $1,600 2025-03-20
Localai MEDIUM 6.1
CVE-2024-48057

localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a …

Fix: after 2.20.1
Fix from $1,600 2024-11-04
Localai CRITICAL 9.8
CVE-2024-6868

mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. When model configurations spe…

Patch available
Fix from $2,300 2024-10-29
Localai MEDIUM 5.9
CVE-2024-7010

mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by…

Patch available
Fix from $1,600 2024-10-29
Localai HIGH 8.8
CVE-2024-6983

mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only f…

Patch available
Fix from $1,950 2024-09-27
Localai MEDIUM 5.8
CVE-2024-6095

A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server-Side Request Forgery (SSRF) and partial Local File …

Fix: 2.17.0+
Fix from $1,600 2024-07-06
Localai CRITICAL 9.8
CVE-2024-5181

A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backen…

Patch available
Fix from $2,300 2024-06-26
Localai CRITICAL 9.1
CVE-2024-5182EPSS 26%

A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion…

Fix: 2.16.0+
Fix from $2,300 2024-06-20
Localai CRITICAL 9.8
CVE-2024-2029

A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioToWav` function used for conver…

Fix: 2.10.0+
Fix from $2,300 2024-04-10
Localai MEDIUM 6.5
CVE-2024-3135

A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when…

Fix: 2.17.0+
Fix from $1,600 2024-04-01