A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when visited by a victim, perform unauthorized actions on the victim's local LocalAI instance without their consent. This vulnerability enables attackers to exhaust system resources, consume credits, and fill disk space by making numerous resource-intensive API calls, such as generating images or uploading files. The vulnerability stems from the application's acceptance of simple request content-types without requiring CSRF tokens or implementing other CSRF mitigation measures. Successful exploitation does not require network access to the vulnerable LocalAI environment.

Project Subscriptions

Vendors Products
Localai Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-1234 A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when visited by a victim, perform unauthorized actions on the victim's local LocalAI instance without their consent. This vulnerability enables attackers to exhaust system resources, consume credits, and fill disk space by making numerous resource-intensive API calls, such as generating images or uploading files. The vulnerability stems from the application's acceptance of simple request content-types without requiring CSRF tokens or implementing other CSRF mitigation measures. Successful exploitation does not require network access to the vulnerable LocalAI environment.
Github GHSA Github GHSA GHSA-jhvf-7c85-3c9g LocalAI cross-site request forgery vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 27 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Mudler
Mudler localai
CPEs cpe:2.3:a:mudler:localai:*:*:*:*:*:*:*:*
Vendors & Products Mudler
Mudler localai

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2024-08-01T19:32:42.865Z

Reserved: 2024-04-01T14:23:45.909Z

Link: CVE-2024-3135

cve-icon Vulnrichment

Updated: 2024-08-01T19:32:42.865Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-01T19:15:46.257

Modified: 2025-06-27T15:58:15.920

Link: CVE-2024-3135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses