Remote Code Execution Vulnerability in Lollms-Webui by Parisneo
CVE-2024-4897

Currently unrated

Key Information:

Vendor
Parisneo
Vendor
CVE Published:
2 July 2024

Summary

The lollms-webui application from Parisneo is susceptible to a remote code execution vulnerability due to an insecure dependency on the llama-cpp-python library. This issue is linked to the application's 'binding_zoo' feature, which enables malicious users to upload and execute harmful model files sourced from platforms like Hugging Face. The vulnerability exploits the handling of gguf format model files, particularly in a scenario where the known vulnerability in llama-cpp-python remains unaddressed in the latest version of lollms-webui.

References

Timeline

  • Vulnerability published

.