Vulnerability GHSA-8c5q-hx4g-qq23

High Risk
HIGH RISK
CVSS Score: 8.6
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 months ago
July 07, 2026 at 09:31 PM UTC
LocalAI POST /models/apply permits unauthenticated server-side request forgery through gallery URLs
v0.8.1 - v1.40.0
v0.8.1 - v1.40.0

Summary

LocalAI POST /models/apply permits unauthenticated server-side request forgery through gallery URLs

Details

LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized gallery URL fields directly to gallery.GetGalleryConfigFromURLWithContext without proper validation, enabling attackers to force the server to issue HTTP GET requests to private and loopback ranges with partial response content leaked through error messages.

Impacted packages

Timeline

Published
2 months ago
July 07, 2026 at 09:31 PM UTC
Last Modified
4 hours ago
October 02, 2026 at 07:30 PM UTC