Vulnerability GHSA-8c5q-hx4g-qq23
High Risk
HIGH RISK
CVSS Score: 8.6
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 months ago
July 07, 2026 at 09:31 PM UTC
LocalAI POST /models/apply permits unauthenticated server-side request forgery through gallery URLs
v0.8.1 - v1.40.0
v0.8.1 - v1.40.0
Summary
LocalAI POST /models/apply permits unauthenticated server-side request forgery through gallery URLs
Details
LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized gallery URL fields directly to gallery.GetGalleryConfigFromURLWithContext without proper validation, enabling attackers to force the server to issue HTTP GET requests to private and loopback ranges with partial response content leaked through error messages.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
1 year ago
LocalAI Cross-Site Scripting (XSS) vulnerability in its search functionality in github.com/mudler/LocalAI
v0.8.1 - v1.40.0 GO-2025-3542
v0.8.1 - v1.40.0 GO-2025-3542
Medium Risk
1 year ago
LocalAI Cross-Site Scripting (XSS) vulnerability in its search functionality
v0.8.1 - v1.40.0 GHSA-w6hh-w36c-vxmw
v0.8.1 - v1.40.0 GHSA-w6hh-w36c-vxmw
Unknown
1 year ago
LocalAI Cross-site Scripting vulnerability in github.com/mudler/LocalAI
v0.8.1 - v1.40.0 GO-2024-3253
v0.8.1 - v1.40.0 GO-2024-3253
Medium Risk
1 year ago
LocalAI Cross-site Scripting vulnerability
v0.8.1 - v1.40.0 GHSA-ghx4-cgxw-7h9p
v0.8.1 - v1.40.0 GHSA-ghx4-cgxw-7h9p
Impacted packages
Timeline
Published
2 months ago
July 07, 2026 at 09:31 PM UTC
Last Modified
4 hours ago
October 02, 2026 at 07:30 PM UTC