A Cross-Site Request Forgery (CSRF) vulnerability exists in mudler/LocalAI versions up to and including 2.15.0, which allows attackers to trick victims into deleting installed models. By crafting a malicious HTML page, an attacker can cause the deletion of a model, such as 'gpt-4-vision-preview', without the victim's consent. The vulnerability is due to insufficient CSRF protection mechanisms on the model deletion functionality.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-07-06T08:38:02.339Z
Updated: 2024-08-01T21:18:06.438Z
Reserved: 2024-06-04T02:49:35.920Z
Link: CVE-2024-5616
Vulnrichment
Updated: 2024-08-01T21:18:06.438Z
NVD
Status : Awaiting Analysis
Published: 2024-07-06T09:15:02.050
Modified: 2024-07-08T15:49:22.437
Link: CVE-2024-5616
Redhat
No data.