Skip to content
LocalAIGHSA-ghx4-cgxw-7h9p

LocalAI Cross-site Scripting vulnerability

Low6.1CVE-2024-48057 · Published Nov 5, 2024 · updated Mar 20, 2025

localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage XSS, which will trigger the payload when a user accesses the homepage.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/mudler/LocalAI
Go
<= 2.20.1No fix yet
Details and references

More LocalAI advisories

All LocalAI
Advisory
LocalAI Cross-Site Scripting (XSS) vulnerability in its search functionality
Medium5.4Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.