A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when visited by a victim, perform unauthorized actions on the victim's local LocalAI instance without their consent. This vulnerability enables attackers to exhaust system resources, consume credits, and fill disk space by making numerous resource-intensive API calls, such as generating images or uploading files. The vulnerability stems from the application's acceptance of simple request content-types without requiring CSRF tokens or implementing other CSRF mitigation measures. Successful exploitation does not require network access to the vulnerable LocalAI environment.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1234 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when visited by a victim, perform unauthorized actions on the victim's local LocalAI instance without their consent. This vulnerability enables attackers to exhaust system resources, consume credits, and fill disk space by making numerous resource-intensive API calls, such as generating images or uploading files. The vulnerability stems from the application's acceptance of simple request content-types without requiring CSRF tokens or implementing other CSRF mitigation measures. Successful exploitation does not require network access to the vulnerable LocalAI environment. |
Github GHSA |
GHSA-jhvf-7c85-3c9g | LocalAI cross-site request forgery vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 27 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mudler
Mudler localai |
|
| CPEs | cpe:2.3:a:mudler:localai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mudler
Mudler localai |
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T19:32:42.865Z
Reserved: 2024-04-01T14:23:45.909Z
Link: CVE-2024-3135
Updated: 2024-08-01T19:32:42.865Z
Status : Analyzed
Published: 2024-04-01T19:15:46.257
Modified: 2025-06-27T15:58:15.920
Link: CVE-2024-3135
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA