Remote Code Execution Vulnerability in Lollms-Webui
CVE-2024-2366
9CRITICAL
What is CVE-2024-2366?
A vulnerability exists within the parisneo/lollms-webui application that allows for remote code execution through improper path sanitization in the reinstall_binding functionality. The issue is located in the lollms_core module, specifically in the lollms/server/endpoints/lollms_binding_infos.py script. Attackers can exploit this vulnerability by manipulating the binding_path variable, enabling them to direct the application to unintended directories. By uploading a crafted init.py file to a controlled directory, an attacker could gain the capability to execute arbitrary code, posing significant risks to the integrity and security of the server.
Affected Version(s)
parisneo/lollms-webui <= unspecified