A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate requests, enabling an attacker to craft a malicious webpage that, when visited by a victim, submits a form to the victim's local lollms-webui instance to execute arbitrary OS commands. This issue allows attackers to take full control of the victim's system without requiring direct network access to the vulnerable application.
History

Mon, 30 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Parisneo
Parisneo lollms-webui
CPEs cpe:2.3:a:parisneo:lollms-webui:*:*:*:*:*:*:*:*
Vendors & Products Parisneo
Parisneo lollms-webui

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-03-30T18:02:59.260Z

Updated: 2024-08-01T18:40:21.324Z

Reserved: 2024-02-14T23:31:53.478Z

Link: CVE-2024-1522

cve-icon Vulnrichment

Updated: 2024-08-01T18:40:21.324Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-30T18:15:45.930

Modified: 2025-06-30T18:56:13.953

Link: CVE-2024-1522

cve-icon Redhat

No data.