Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1234 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when visited by a victim, perform unauthorized actions on the victim's local LocalAI instance without their consent. This vulnerability enables attackers to exhaust system resources, consume credits, and fill disk space by making numerous resource-intensive API calls, such as generating images or uploading files. The vulnerability stems from the application's acceptance of simple request content-types without requiring CSRF tokens or implementing other CSRF mitigation measures. Successful exploitation does not require network access to the vulnerable LocalAI environment. |
Github GHSA |
GHSA-jhvf-7c85-3c9g | LocalAI cross-site request forgery vulnerability |
Fri, 27 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mudler
Mudler localai |
|
| CPEs | cpe:2.3:a:mudler:localai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mudler
Mudler localai |
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T19:32:42.865Z
Reserved: 2024-04-01T14:23:45.909Z
Link: CVE-2024-3135
Updated: 2024-08-01T19:32:42.865Z
Status : Analyzed
Published: 2024-04-01T19:15:46.257
Modified: 2026-06-17T07:43:22.680
Link: CVE-2024-3135
No data.
OpenCVE Enrichment
No data.
-
CWE-352
Cross-Site Request Forgery (CSRF)
EUVD
Github GHSA