CVE-2024-2029 Information
Apr 11, 2024
cve
Description
A command injection vulnerability exists in the TranscriptEndpoint of mudler/localai specifically within the audioToWav function used for converting audio files to WAV format for transcription. The vulnerability arises due to the lack of sanitization of user-supplied filenames before passing them to ffmpeg via a shell command allowing an attacker to execute arbitrary commands on the host system. Successful exploitation could lead to unauthorized access data breaches or other detrimental impacts depending on the privileges of the process executing the code.
Reference
https://huntr.com/bounties/e092528a-ce3b-4e66-9b98-3f56d6b276b0 https://github.com/mudler/localai/commit/31a4c9c9d3abc58de2bdc5305419181c8b33eb1c
Share on: