// For flags

CVE-2024-6095

SSRF and Partial LFI in /models/apply Endpoint in mudler/localai

Severity Score

5.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server-Side Request Forgery (SSRF) and partial Local File Inclusion (LFI). The endpoint supports both http(s):// and file:// schemes, where the latter can lead to LFI. However, the output is limited due to the length of the error message. This vulnerability can be exploited by an attacker with network access to the LocalAI instance, potentially allowing unauthorized access to internal HTTP(s) servers and partial reading of local files. The issue is fixed in version 2.17.

Una vulnerabilidad en el endpoint /models/apply de mudler/localai versiones 2.15.0 permite Server Side Request Forgery (SSRF) y la inclusión parcial de archivos locales (LFI). El endpoint admite los esquemas http(s):// y file://, donde este último puede conducir a LFI. Sin embargo, el resultado es limitado debido a la longitud del mensaje de error. Esta vulnerabilidad puede ser aprovechada por un atacante con acceso de red a la instancia de LocalAI, lo que podría permitir el acceso no autorizado a servidores HTTP internos y la lectura parcial de archivos locales. El problema se solucionó en la versión 2.17.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
Poc
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-06-17 CVE Reserved
  • 2024-07-06 CVE Published
  • 2024-08-01 CVE Updated
  • 2024-08-01 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mudler
Search vendor "Mudler"
Localai
Search vendor "Mudler" for product "Localai"
< 2.17.0
Search vendor "Mudler" for product "Localai" and version " < 2.17.0"
-
Affected