← Back

CVE-2024-6983

nvd nist
Published: Sep 27, 2024Modified: Jul 10, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: security@huntr.dev (Secondary)

Description

mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only from the configuration file but also from other inputs, allowing an attacker to upload a binary file and execute malicious code. This can lead to the attacker gaining full control over the system.

Affected (1)

Products: Mudler: Localai
1 product
Localai
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.17.1

References (2)

Timeline

No history available yet.