Database/AI/ML frameworks & serving
OpenLLM: Local file inclusion via the web application
CVSS 6.2CVE-2024-8982AI/ML frameworks & servingcurated
Impact
Local file inclusion via the web application
Who can reach it
Network user of the OpenLLM UI
What to do
Upgrade past 0.6.10
References
Related entries
- Weights & Biases OpenUI: Unauthenticated endpoints allow file upload and downloadCVE-2024-10649 · Weights & Biases OpenUIMedium
- Dask distributed (+ Jupyter proxy): Exposure when Dask, JupyterLab and jupyter-server-proxy are combinedCVE-2026-23528 · Dask distributed (+ Jupyter proxy)Medium
- tract: unchecked size multiplication when reading an NNEF tensor gives a heap over-read on model loadCVE-2026-55093 · tract-nnef (read_tensor in nnef/src/tensors.rs)Medium
- tract: ONNX external_data path is not sanitised, so loading a model reads arbitrary local filesCVE-2026-55832 · tract-onnx (external_data path handling, get_external_resources / MmapDataResolver)Medium
- BentoML 1.3.9 (open redirect in the serving UI): A crafted URL against the BentoML server bounces the visitor to anNCVD-2025-017-bentoml-1-3-9-open-redirect-in-t · BentoML 1.3.9 (open redirect in the serving UI)Medium
- ClearML: Passwords stored in plaintext in MongoDBCVE-2024-24595 · ClearMLMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.