This hands-on PoC shows how I got an open-source model running locally in Visual Studio Code, where the setup worked, where it broke down, and what to watch out for if you want to apply a local model ...
Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution.