PT-2024-19946 · Unknown · Parisneo/Lollms-Webui

Published

2024-05-16

·

Updated

2025-07-09

·

CVE-2024-2358

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions parisneo/lollms-webui (affected versions not specified)
Description A path traversal issue exists due to insufficient sanitization of user-supplied input in the configuration settings, specifically within the extensions parameter of the "/apply settings" endpoint. This allows attackers to execute arbitrary code by crafting a payload with relative path traversal sequences, enabling them to navigate to arbitrary directories and load a malicious ' init .py' file, leading to remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-2358

Affected Products

Parisneo/Lollms-Webui