LocalAI version v2.19.4 (af0545834fd565ab56af0b9348550ca9c3cb5349) contains a vulnerability where the delete model API improperly neutralizes input during web page generation, leading to a one-time storage cross-site scripting (XSS) vulnerability. This vulnerability allows an attacker to store a malicious payload that executes when a user accesses the homepage. Additionally, the presence of cross-site request forgery (CSRF) can enable automated malicious requests.
History

Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description LocalAI version v2.19.4 (af0545834fd565ab56af0b9348550ca9c3cb5349) contains a vulnerability where the delete model API improperly neutralizes input during web page generation, leading to a one-time storage cross-site scripting (XSS) vulnerability. This vulnerability allows an attacker to store a malicious payload that executes when a user accesses the homepage. Additionally, the presence of cross-site request forgery (CSRF) can enable automated malicious requests.
Title Storage XSS and CSRF Vulnerability in mudler/localai
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 3.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-03-20T10:11:01.980Z

Updated: 2025-03-20T18:13:58.234Z

Reserved: 2024-10-12T01:09:41.237Z

Link: CVE-2024-9901

cve-icon Vulnrichment

Updated: 2025-03-20T17:47:39.757Z

cve-icon NVD

Status : Received

Published: 2025-03-20T10:15:50.540

Modified: 2025-03-20T10:15:50.540

Link: CVE-2024-9901

cve-icon Redhat

No data.