Description
A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerability arises due to insufficient sanitization of user-supplied input in the configuration settings, specifically within the 'extensions' parameter. Attackers can exploit this by crafting a payload that includes relative path traversal sequences ('../../../'), enabling them to navigate to arbitrary directories. This flaw subsequently allows the server to load and execute a malicious '__init__.py' file, leading to remote code execution. The issue affects the latest version of parisneo/lollms-webui.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27311 | A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerability arises due to insufficient sanitization of user-supplied input in the configuration settings, specifically within the 'extensions' parameter. Attackers can exploit this by crafting a payload that includes relative path traversal sequences ('../../../'), enabling them to navigate to arbitrary directories. This flaw subsequently allows the server to load and execute a malicious '__init__.py' file, leading to remote code execution. The issue affects the latest version of parisneo/lollms-webui. |
References
History
Wed, 09 Jul 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lollms
Lollms lollms Web Ui |
|
| CPEs | cpe:2.3:a:lollms:lollms_web_ui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lollms
Lollms lollms Web Ui |
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T19:11:53.476Z
Reserved: 2024-03-09T22:49:41.242Z
Link: CVE-2024-2358
Updated: 2024-08-01T19:11:53.476Z
Status : Analyzed
Published: 2024-05-16T09:15:09.800
Modified: 2025-07-09T14:39:33.337
Link: CVE-2024-2358
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD