Home » Database

AVID-2026-R1556

Description

XSS and Open Redirect via SVG File Upload in parisneo/lollms-webui (CVE-2024-5125)

Details

parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of SVG files during the upload process. The XSS vulnerability allows attackers to embed malicious JavaScript code within SVG files, which is executed upon rendering, leading to potential credential theft and unauthorized data access. The Open Redirect vulnerability arises from insufficient URL validation within SVG files, enabling attackers to redirect users to malicious websites, thereby exposing them to phishing attacks, malware distribution, and reputation damage. These vulnerabilities are present in the application’s functionality to send files to the AI module.

Reason for inclusion in AVID: The CVE describes XSS and Open Redirect vulnerabilities in parisneo/lollms-webui, a web UI component used to interact with and deploy AI models. This is a software vulnerability within an AI software stack (deployment/serving interface) that could impact AI systems. The issue is relevant to AI supply chains as it affects components used to build/run AI workloads, with clear security implications. The report provides explicit vulnerability details, CVE metadata, and references.

References

Affected or Relevant Artifacts

  • Developer: parisneo
  • Deployer: parisneo
  • Artifact Details:
TypeName
Systemparisneo/lollms-webui

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.0
Vector StringCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H
Base Score7.3
Base Severity🔴 High
Attack VectorLOCAL
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality Impact🟢 Low
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-79CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-11-14
  • Version: 0.3.3
  • AVID Entry