A Cross-Site Request Forgery (CSRF) vulnerability exists in mudler/LocalAI versions up to and including 2.15.0, which allows attackers to trick victims into deleting installed models. By crafting a malicious HTML page, an attacker can cause the deletion of a model, such as 'gpt-4-vision-preview', without the victim's consent. The vulnerability is due to insufficient CSRF protection mechanisms on the model deletion functionality.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-07-06T08:38:02.339Z
Updated: 2024-08-01T21:18:06.438Z
Reserved: 2024-06-04T02:49:35.920Z
Link: CVE-2024-5616

Updated: 2024-08-01T21:18:06.438Z

Status : Awaiting Analysis
Published: 2024-07-06T09:15:02.050
Modified: 2024-11-21T09:48:01.540
Link: CVE-2024-5616

No data.