CVE-2024-6095 is a Server-Side Request Forgery (SSRF) and partial Local File Inclusion (LFI) vulnerability affecting mudler/localai versions 2.15.0 and earlier. An unauthenticated attacker with network access can exploit the /models/apply endpoint to access internal HTTP(s) resources or partially read local files, though output is limited by error message length. Rated Medium severity (CVSS 5.8), this vulnerability has a high EPSS score (0.88974) and FAUCET Risk Score (99/100), indicating a significant threat. While not listed in KEV or Hot Lists, Nuclei templates exist for partial LFI, suggesting potential for exploitation; however, there is no public exploit code or community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.17.0CPE matchmatch criteria | cpe:2.3:a:mudler:localai:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.