Cross-Site Scripting Vulnerability in localai by mudler
CVE-2024-9900

6.1MEDIUM

Key Information:

Vendor
Mudler
Vendor
CVE Published:
20 March 2025

Summary

The localai version v2.21.1 by mudler has a notable Cross-Site Scripting (XSS) vulnerability in its search functionality. This issue stems from inadequate sanitization of user inputs, which permits attackers to inject and execute arbitrary JavaScript code. Such exploitation could enable the execution of harmful scripts within the victim's browser context, leading to severe security risks such as user session hijacking, cookie theft, unwanted redirects to malicious sites, or unauthorized manipulation of the Document Object Model (DOM).

Affected Version(s)

mudler/localai < 2.22.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

CVSS V3.0

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.