CVE-2024-2361

CRITICAL

lollms_web_ui < 9.5 - Path Traversal and Arbitrary File Upload via install_model() Function

Title source: llm
STIX 2.1

Description

A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization of user-supplied input. Specifically, the issue resides in the `install_model()` function within `lollms_core/lollms/binding.py`, where the application fails to properly sanitize the `file://` protocol and other inputs, leading to arbitrary read and upload capabilities. Attackers can exploit this vulnerability by manipulating the `path` and `variant_name` parameters to achieve path traversal, allowing for the reading of arbitrary files and uploading files to arbitrary locations on the server. This vulnerability affects the latest version of parisneo/lollms-webui.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Patch, Third Party Advisory
https://huntr.com/bounties/cd383817-924a-445a-838e-d0c867c6a176

Scores

CVSS v3 9.6
EPSS 0.0063
EPSS Percentile 45.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-29
Status published
Products (1)
lollms/lollms_web_ui < 9.5
Published May 16, 2024
Tracked Since Feb 18, 2026