Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in mudler/LocalAI versions up to and including 2.15.0, which allows attackers to trick victims into deleting installed models. By crafting a malicious HTML page, an attacker can cause the deletion of a model, such as 'gpt-4-vision-preview', without the victim's consent. The vulnerability is due to insufficient CSRF protection mechanisms on the model deletion functionality.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46799 | A Cross-Site Request Forgery (CSRF) vulnerability exists in mudler/LocalAI versions up to and including 2.15.0, which allows attackers to trick victims into deleting installed models. By crafting a malicious HTML page, an attacker can cause the deletion of a model, such as 'gpt-4-vision-preview', without the victim's consent. The vulnerability is due to insufficient CSRF protection mechanisms on the model deletion functionality. |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mudler
Mudler localai |
|
| CPEs | cpe:2.3:a:mudler:localai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mudler
Mudler localai |
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T21:18:06.438Z
Reserved: 2024-06-04T02:49:35.920Z
Link: CVE-2024-5616
Updated: 2024-08-01T21:18:06.438Z
Status : Analyzed
Published: 2024-07-06T09:15:02.050
Modified: 2025-07-15T13:24:01.330
Link: CVE-2024-5616
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:47Z
Weaknesses
EUVD