Cross-Site Scripting Vulnerability in localai by mudler
CVE-2024-9900
6.1MEDIUM
Summary
The localai version v2.21.1 by mudler has a notable Cross-Site Scripting (XSS) vulnerability in its search functionality. This issue stems from inadequate sanitization of user inputs, which permits attackers to inject and execute arbitrary JavaScript code. Such exploitation could enable the execution of harmful scripts within the victim's browser context, leading to severe security risks such as user session hijacking, cookie theft, unwanted redirects to malicious sites, or unauthorized manipulation of the Document Object Model (DOM).
Affected Version(s)
mudler/localai < 2.22.0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
CVSS V3.0
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved