Local File Inclusion Flaw in OpenLLM by OpenLLM Team
CVE-2024-8982

6.2MEDIUM

Key Information:

Vendor

Bentoml

Vendor
CVE Published:
20 March 2025

What is CVE-2024-8982?

A Local File Inclusion (LFI) vulnerability is present in OpenLLM version 0.6.10, enabling attackers to include files from the local server via the web application. This significant flaw permits unauthorized access to critical server files, including but not limited to configuration files, user credentials, and private keys. Such access can expose sensitive information, allowing attackers the potential to manipulate data, escalate privileges, and deeply compromise the system's security. By exploiting this vulnerability, attackers could gain further control of the network and exfiltrate sensitive data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

bentoml/openllm <= unspecified

References

CVSS V3.0

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.