A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate requests, enabling an attacker to craft a malicious webpage that, when visited by a victim, submits a form to the victim's local lollms-webui instance to execute arbitrary OS commands. This issue allows attackers to take full control of the victim's system without requiring direct network access to the vulnerable application.
Metrics
Affected Vendors & Products
References
History
Mon, 30 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Parisneo
Parisneo lollms-webui |
|
CPEs | cpe:2.3:a:parisneo:lollms-webui:*:*:*:*:*:*:*:* | |
Vendors & Products |
Parisneo
Parisneo lollms-webui |

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-03-30T18:02:59.260Z
Updated: 2024-08-01T18:40:21.324Z
Reserved: 2024-02-14T23:31:53.478Z
Link: CVE-2024-1522

Updated: 2024-08-01T18:40:21.324Z

Status : Analyzed
Published: 2024-03-30T18:15:45.930
Modified: 2025-06-30T18:56:13.953
Link: CVE-2024-1522

No data.