A vulnerability in parisneo/lollms-webui versions up to 9...
Critical severity
Unreviewed
Published
May 16, 2024
to the GitHub Advisory Database
•
Updated May 16, 2024
Description
Published by the National Vulnerability Database
May 16, 2024
Published to the GitHub Advisory Database
May 16, 2024
Last updated
May 16, 2024
A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the
/apply_settings
and/execute_code
endpoints. Attackers can bypass protections by setting the host to localhost, enabling code execution, and disabling code validation through the/apply_settings
endpoint. Subsequently, arbitrary commands can be executed remotely via the/execute_code
endpoint, exploiting the delay in settings enforcement. This issue was addressed in version 9.5.References