CVE-2024-6983
CVSS 3.0 Score 8.8 of 10 (high)
Details
Published Sep 27, 2024
Updated: Sep 30, 2024
CWE ID 94
Summary
CVE-2024-6983 is a remote code execution vulnerability affecting mudler/localai version 2.17.1. The issue stems from the localai backend's handling of inputs, which extends beyond configuration files. An attacker can exploit this by uploading a malicious binary file, resulting in the execution of arbitrary code. This vulnerability exposes the targeted system to potential takeover by the attacker.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.