Vulnerability GHSA-ghx4-cgxw-7h9p

Medium Risk
MEDIUM RISK
CVSS Score: 6.1
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 year ago
November 05, 2024 at 12:31 AM UTC
LocalAI Cross-site Scripting vulnerability
v0.8.1 - v1.40.0
v0.8.1 - v1.40.0

Summary

LocalAI Cross-site Scripting vulnerability

Details

localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage XSS, which will trigger the payload when a user accesses the homepage.

Impacted packages

Timeline

Published
1 year ago
November 05, 2024 at 12:31 AM UTC
Last Modified
1 year ago
March 20, 2025 at 11:22 PM UTC