Unauthorized Directory Deletion Vulnerability in parisneo/lollms-webui
CVE-2024-9919

8.4HIGH

Key Information:

Vendor
Parisneo
Vendor
CVE Published:
20 March 2025

Summary

A security issue in parisneo/lollms-webui V13 stems from a missing authentication verification in its API's uninstall endpoint. This flaw allows unauthorized users to delete directories by accessing the /uninstall/{app_name} endpoint without proper authentication. The absence of a call to the check_access() function for client validation poses a serious risk, enabling malicious actors to manipulate the application's directory structures without any authentication checks in place.

Affected Version(s)

parisneo/lollms-webui <= unspecified

References

CVSS V3.0

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.