Home » Database

AVID-2026-R1528

Description

Remote Code Execution via /apply_settings and /execute_code in parisneo/lollms-webui (CVE-2024-4326)

Details

A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the /apply_settings and /execute_code endpoints. Attackers can bypass protections by setting the host to localhost, enabling code execution, and disabling code validation through the /apply_settings endpoint. Subsequently, arbitrary commands can be executed remotely via the /execute_code endpoint, exploiting the delay in settings enforcement. This issue was addressed in version 9.5.

Reason for inclusion in AVID: CVE-2024-4326 describes a remote code execution vulnerability in the parisneo/lollms-webui web UI, allowing attackers to execute arbitrary commands via exposed endpoints. This is a software vulnerability directly affecting an AI deployment/serving stack component, with clear impact on AI systems. The affected component is used in building/deploying AI workloads, thus relevant to the general-purpose AI supply chain. The report provides explicit vulnerability details, affected versions, exploit path, CVSS scores, and remediation, giving sufficient signal for curation.

References

Affected or Relevant Artifacts

  • Developer: parisneo
  • Deployer: parisneo
  • Artifact Details:
TypeName
Systemparisneo/lollms-webui

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.0
Vector StringCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score9.8
Base Severity🔴 Critical
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality Impact🔴 High
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-15CWE-15 External Control of System or Configuration Setting

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-05-16
  • Version: 0.3.3
  • AVID Entry