peter bassill · operator
$ cve CVE-2024-4320 JSON

CVE-2024-4320

9.8
CRITICAL · CVSS 3.1 · EPSS 34.4% (pctl 98)

Patch early

EPSS 34.4% — above the 10% action threshold.

Description

A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. The vulnerability arises due to improper handling of the `name` parameter in the `ExtensionBuilder().build_extension()` method, which allows for local file inclusion (LFI) leading to arbitrary code execution. An attacker can exploit this vulnerability by crafting a malicious `name` parameter that causes the server to load and execute a `__init__.py` file from an arbitrary location, such as the upload directory for discussions. This vulnerability affects the latest version of parisneo/lollms-webui and can lead to remote code execution without requiring user interaction, especially when the application is exposed to an external endpoint or operated in headless mode.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS34.35% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-29
On CISA KEVno
Public exploitnone known
Published2024-06-06
Last modified2026-06-17

Affected (1)

VendorProduct
lollmslollms web ui

References

→ the Explorer  ·  watch your stack  ·  NVD