LocalAI has an unauthenticated server-side request forgery (SSRF) vulnerability in its POST /models/apply endpoint. (CVE-2026-59707)
LocalAI has an unauthenticated server-side request forgery (SSRF) vulnerability in its POST /models/apply endpoint. This flaw allows attackers to supply unsanitized gallery URL fields that are passed directly to an internal function without validation. As a result, attackers can cause the server to make HTTP GET requests to internal or private network addresses, potentially exposing partial response data through error messages. No affected versions or patches are currently specified.
AI Analysis
Technical Summary
The vulnerability in LocalAI involves the POST /models/apply endpoint, where user-supplied gallery URL parameters are forwarded without proper sanitization to gallery.GetGalleryConfigFromURLWithContext. This enables unauthenticated attackers to perform SSRF attacks by forcing the server to issue HTTP GET requests to arbitrary internal or loopback network addresses. Partial response content leakage occurs via error messages. The vulnerability is tracked as CVE-2026-59707 and classified under CWE-918 (Server-Side Request Forgery). No patch or remediation details are currently available, and the service is not cloud-hosted, so remediation depends on vendor action.
Potential Impact
An attacker can exploit this SSRF vulnerability without authentication to make the LocalAI server send HTTP requests to internal or private network resources. This can lead to unauthorized information disclosure through error message leakage and potentially facilitate further attacks against internal systems. The vulnerability is rated critical due to its unauthenticated nature and high impact on confidentiality.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict network access to the LocalAI server to trusted users and networks to limit exposure. Monitor for unusual outbound HTTP requests from the server. Avoid exposing the vulnerable endpoint to untrusted networks.
LocalAI has an unauthenticated server-side request forgery (SSRF) vulnerability in its POST /models/apply endpoint. (CVE-2026-59707)
Description
LocalAI has an unauthenticated server-side request forgery (SSRF) vulnerability in its POST /models/apply endpoint. This flaw allows attackers to supply unsanitized gallery URL fields that are passed directly to an internal function without validation. As a result, attackers can cause the server to make HTTP GET requests to internal or private network addresses, potentially exposing partial response data through error messages. No affected versions or patches are currently specified.
CVSS v4.0
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in LocalAI involves the POST /models/apply endpoint, where user-supplied gallery URL parameters are forwarded without proper sanitization to gallery.GetGalleryConfigFromURLWithContext. This enables unauthenticated attackers to perform SSRF attacks by forcing the server to issue HTTP GET requests to arbitrary internal or loopback network addresses. Partial response content leakage occurs via error messages. The vulnerability is tracked as CVE-2026-59707 and classified under CWE-918 (Server-Side Request Forgery). No patch or remediation details are currently available, and the service is not cloud-hosted, so remediation depends on vendor action.
Potential Impact
An attacker can exploit this SSRF vulnerability without authentication to make the LocalAI server send HTTP requests to internal or private network resources. This can lead to unauthorized information disclosure through error message leakage and potentially facilitate further attacks against internal systems. The vulnerability is rated critical due to its unauthenticated nature and high impact on confidentiality.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict network access to the LocalAI server to trusted users and networks to limit exposure. Monitor for unusual outbound HTTP requests from the server. Avoid exposing the vulnerable endpoint to untrusted networks.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8c5q-hx4g-qq23
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-59707"]
- Ecosystems
- []
- Database Specific Severity
- CRITICAL
- Cvss Version
- 4.0
Threat ID: 6a4e4eedc9d9e3dbe3289f5e
Added to database: 07/08/2026, 13:21:49 UTC
Last enriched: 07/08/2026, 13:41:59 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.