CVE-2024-4078 Information
May 17, 2024
cve
Description
A vulnerability in the parisneo/lollms specifically in the /unInstall_binding endpoint allows for arbitrary code execution due to insufficient sanitization of user input. The issue arises from the lack of path sanitization when handling the name parameter in the unInstall_binding function allowing an attacker to traverse directories and execute arbitrary code by loading a malicious __init__.py file. This vulnerability affects the latest version of the software. The exploitation of this vulnerability could lead to remote code execution on the system where parisneo/lollms is deployed.
Reference
https://huntr.com/bounties/a55a8c04-df44-49b2-bcfa-2a2b728a299d https://github.com/parisneo/lollms/commit/7ebe08da7e0026b155af4f7be1d6417bc64cf02f
Share on: