Skip to main content

Vendor archive

mudler CVEs

Beta · best-effort

11 CVEs tagged to vendor mudler4 Critical, 1 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2024-9900

Published Mar 20, 2025

mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vulnerability arises due to improper sanitization of user input…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48057

Published Nov 4, 2024

localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage XSS, which wi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7010

Published Oct 29, 2024

mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to e…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6868

Published Oct 29, 2024

mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. When model configurations specify additional files as archi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6983

Published Sep 27, 2024

mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only from the configuration file but…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6095

Published Jul 6, 2024

A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server-Side Request Forgery (SSRF) and partial Local File Inclusion (LFI). The endpoint…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5616

Published Jul 6, 2024

A Cross-Site Request Forgery (CSRF) vulnerability exists in mudler/LocalAI versions up to and including 2.15.0, which allows attackers to trick victims into deleting installed mod…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5181

Published Jun 26, 2024

A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backend parameter in the configurati…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5182

Published Jun 20, 2024

A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parameter during the model deletion process to delete arbitrary f…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-2029

Published Apr 10, 2024

A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioToWav` function used for converting audio files to WAV format…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-3135

Published Apr 1, 2024

A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when visited by a victim, perform…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1