cvedb.io
CVE-2024-5181
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2024-06-26T03:15:10.987 · Last modified 2026-06-17T08:15:21.630

Summary

A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backend parameter in the configuration file, which is used in the name of the initialized process. An attacker can exploit this vulnerability by manipulating the path of the vulnerable binary file specified in the backend parameter, allowing the execution of arbitrary code on the system. This issue is due to improper neutralization of special elements used in an OS command, leading to potential full control over the affected system.

Affected products

mudler — localai

Does this affect you?

Add your gear to cvedb and we'll alert you only when mudler ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.