CVE-2024-48057: Mudler Localai
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a one-time storage XSS, which will trigger the payload when a user accesses the homepage.
Affected products
- Mudler Localai: up to and including 2.20.1
Published 2024-11-04. Last modified 2026-06-17.