Remote Code Execution Vulnerability in Lollms-Webui by Parisneo
CVE-2024-4897
Currently unrated
Summary
The lollms-webui application from Parisneo is susceptible to a remote code execution vulnerability due to an insecure dependency on the llama-cpp-python library. This issue is linked to the application's 'binding_zoo' feature, which enables malicious users to upload and execute harmful model files sourced from platforms like Hugging Face. The vulnerability exploits the handling of gguf format model files, particularly in a scenario where the known vulnerability in llama-cpp-python remains unaddressed in the latest version of lollms-webui.
References
Timeline
Vulnerability published