Description
A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerability arises due to insufficient sanitization of user-supplied input in the configuration settings, specifically within the 'extensions' parameter. Attackers can exploit this by crafting a payload that includes relative path traversal sequences ('../../../'), enabling them to navigate to arbitrary directories. This flaw subsequently allows the server to load and execute a malicious '__init__.py' file, leading to remote code execution. The issue affects the latest version of parisneo/lollms-webui.
Published: 2024-05-16
Score: 9.8 Critical
EPSS: 3.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-27311 A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerability arises due to insufficient sanitization of user-supplied input in the configuration settings, specifically within the 'extensions' parameter. Attackers can exploit this by crafting a payload that includes relative path traversal sequences ('../../../'), enabling them to navigate to arbitrary directories. This flaw subsequently allows the server to load and execute a malicious '__init__.py' file, leading to remote code execution. The issue affects the latest version of parisneo/lollms-webui.
History

Wed, 09 Jul 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Lollms
Lollms lollms Web Ui
CPEs cpe:2.3:a:lollms:lollms_web_ui:*:*:*:*:*:*:*:*
Vendors & Products Lollms
Lollms lollms Web Ui

Subscriptions

Lollms Lollms Web Ui
cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2024-08-01T19:11:53.476Z

Reserved: 2024-03-09T22:49:41.242Z

Link: CVE-2024-2358

cve-icon Vulnrichment

Updated: 2024-08-01T19:11:53.476Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-16T09:15:09.800

Modified: 2025-07-09T14:39:33.337

Link: CVE-2024-2358

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses