CVE-2024-5181
Last modified
CVE-2024-5181 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backend parameter in the configuration file, which is used in the name of the initialized process. EPSS estimates a 2.69% chance of exploitation in the next 30 days.
Description
A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backend parameter in the configuration file, which is used in the name of the initialized process. An attacker can exploit this vulnerability by manipulating the path of the vulnerable binary file specified in the backend parameter, allowing the execution of arbitrary code on the system. This issue is due to improper neutralization of special elements used in an OS command, leading to potential full control over the affected system.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mudler | Localai | 2.14.0 |
References
- https://huntr.com/bounties/c6e3cb58-6fa4-4207-bb92-ae7644174661Exploit, Third Party Advisory
- https://huntr.com/bounties/c6e3cb58-6fa4-4207-bb92-ae7644174661Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-5181?
How severe is CVE-2024-5181?
How do I fix CVE-2024-5181?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-51804Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-51805Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-51806Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-51807Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-51808Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-51809Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-51810Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-51811Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-51812Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-51813Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-51814Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-51815Improper Control of Generation of Code ('Code Injection') vu…9
Are you affected by CVE-2024-5181?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
