Home » Database

AVID-2026-R1639

Description

Missing Authentication Check in parisneo/lollms-webui (CVE-2024-9919)

Details

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.

Reason for inclusion in AVID: CVE-2024-9919 describes a missing authentication check in the parisneo/lollms-webui uninstall endpoint, enabling unauthorized deletion of directories. This affects AI deployment/management tooling used in general-purpose AI systems, i.e., a component in the AI software stack that could be used to build, deploy, or run AI models. It is a security vulnerability with actionable details (endpoint, missing auth, CWE-306, CVSS 3.0 metrics). The report provides sufficient signal to classify it as a software supply-chain vulnerability within AI systems.

References

Affected or Relevant Artifacts

  • Developer: parisneo
  • Deployer: parisneo
  • Artifact Details:
TypeName
Systemparisneo/lollms-webui

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.0
Vector StringCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score8.4
Base Severity🔴 High
Attack VectorLOCAL
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality Impact🔴 High
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-306CWE-306 Missing Authentication for Critical Function

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2025-03-20
  • Version: 0.3.3
  • AVID Entry