The web server lacked CSRF tokens allowing an attacker to host malicious JavaScript on a host that when visited by a LocalAI user, could allow the attacker to fill disk space to deny service or abuse credits.
This Cyber News was published on www.tenable.com. Publication date: Mon, 01 Apr 2024 20:56:03 +0000