CVE-2024-5181 is a critical command injection vulnerability affecting mudler/localai version 2.14.0. It stems from improper handling of the 'backend' parameter in the configuration file, allowing attackers to inject arbitrary commands. With a CVSS score of 9.8 (Critical), this vulnerability can be exploited remotely without user interaction, potentially granting full control over the affected system. While no active exploits, public exploit code, or significant community discussion have been observed, its high severity warrants immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.14.0CPE matchmatch criteria | cpe:2.3:a:mudler:localai:2.14.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.