Junglewise Threat Intelligence

CVE-2026-59707: LocalAI SSRF in models/apply endpoint

CVE-2026-59707 · Severity: high · CVSS 8.6 · Published 2026-07-07

Executive brief

LocalAI is an open-source AI engine that allows users to run various artificial intelligence models on their own hardware. A security flaw in the model installation process allows unauthenticated attackers to trick the server into making unauthorized requests to internal network resources. This could lead to the exposure of sensitive internal data or allow attackers to probe private infrastructure that is otherwise inaccessible from the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in LocalAI's 'POST /models/apply' endpoint due to insufficient validation of the 'url' field in the JSON request body. When the 'id' field is empty, the application passes the unsanitized URL directly to 'gallery.GetGalleryConfigFromURLWithContext', which performs an HTTP GET request using Go's http.Client. Because the application fails to verify if the target URL resolves to a public IP address, an unauthenticated remote attacker can force the server to scan or fetch data from internal loopback (127.0.0.1) or private network ranges. Furthermore, if the requested internal resource returns non-YAML content, the resulting error messages can leak approximately 30 bytes of the response body. The vulnerability is addressed in commit f9b968e.

Affected products

  • LocalAI LocalAI <= v4.3.1

Timeline

  • 2026-06-01: disclosed: Vulnerability reported to vendor via email
  • 2026-07-03: other: Public issue opened on GitHub repository
  • 2026-07-07: advisory: CVE-2026-59707 published

References