Remote Code Execution in Parisneo Lollms Web UI
CVE-2024-9920
What is CVE-2024-9920?
The Lollms Web UI in version 12 enables an insecure file upload functionality that permits the uploading of various file types, including executable scripts such as .py, .sh, and .bat. This can lead to severe security risks as attackers could upload malicious files and execute them through the '/open_file' API endpoint. The root of the issue stems from the failure to properly validate the files being uploaded, resulting in potential remote code execution via subprocess commands. This vulnerability puts users and systems at significant risk if not addressed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
parisneo/lollms-webui <= unspecified
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
