PT-2026-28718 · Localgpt · Localgpt

Vuldb

+1

·

Published

2026-03-28

·

Updated

2026-03-29

·

CVE-2026-5000

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PromtEngineer localGPT versions prior to 4d41c7d1713b16b216d8e062e51a5dd88b20b054
Description A missing authentication issue exists in the LocalGPTHandler function within the API Endpoint component of the software. The manipulation of the BaseHTTPRequestHandler argument leads to this issue. The attack can be executed remotely. The product implements a rolling release, making specific version information unavailable.
Recommendations Versions prior to 4d41c7d1713b16b216d8e062e51a5dd88b20b054 require attention. As a temporary workaround, consider restricting access to the affected API Endpoint until a resolution is available.

Exploit

Fix

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-5000

Affected Products

Localgpt