PT-2024-20009 · Parisneo · Lollms-Webui
Published
2024-05-16
·
Updated
2025-07-09
·
CVE-2024-2366
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
parisneo/lollms-webui version latest
Description
A remote code execution issue exists due to insufficient path sanitization in the reinstall binding functionality. This allows an attacker to exploit path traversal and navigate to arbitrary directories. By manipulating the
binding path to point to a controlled directory and uploading a malicious init .py file, an attacker can execute arbitrary code on the server.Recommendations
For the latest version, consider disabling the reinstall binding functionality until a patch is available to prevent exploitation. Restrict access to the
lollms binding infos.py endpoint to minimize the risk of arbitrary code execution. Avoid using the binding path variable in the affected endpoint until the issue is resolved.Fix
RCE
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lollms-Webui