PT-2026-56257 · Localai · Localai
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LocalAI (affected versions not specified)
Description
An unauthenticated server-side request forgery (SSRF) exists in the 'POST /models/apply' endpoint. This occurs because the endpoint passes unsanitized gallery URL fields to the
gallery.GetGalleryConfigFromURLWithContext() function without proper validation. This allows attackers to force the server to issue HTTP GET requests to private and loopback network ranges, potentially leaking partial response content through error messages.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Localai