Skip to content
LocalAIGHSA-8c5q-hx4g-qq23

LocalAI POST /models/apply permits unauthenticated server-side request forgery through gallery URLs

Critical8.6CVE-2026-59707 · Published Jul 7, 2026 · updated Oct 2, 2026

LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized gallery URL fields directly to gallery.GetGalleryConfigFromURLWithContext without proper validation, enabling attackers to force the server to issue HTTP GET requests to private and loopback ranges with partial response content leaked through error messages.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/mudler/LocalAI
Go
< 1.40.1-0.20260703213242-2cbb3c96b34d1.40.1-0.20260703213242-2cbb3c96b34d
Details and references

More LocalAI advisories

All LocalAI
Advisory
LocalAI Cross-Site Scripting (XSS) vulnerability in its search functionality
Medium5.4Mar 20, 2025
LocalAI Cross-site Scripting vulnerability
Low6.1Nov 5, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.