Cross-Site Scripting Vulnerability in localai by mudler
CVE-2024-9900
What is CVE-2024-9900?
The localai version v2.21.1 by mudler has a notable Cross-Site Scripting (XSS) vulnerability in its search functionality. This issue stems from inadequate sanitization of user inputs, which permits attackers to inject and execute arbitrary JavaScript code. Such exploitation could enable the execution of harmful scripts within the victim's browser context, leading to severe security risks such as user session hijacking, cookie theft, unwanted redirects to malicious sites, or unauthorized manipulation of the Document Object Model (DOM).

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mudler/localai < 2.22.0
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
