Remote Code Execution in parisneo/lollms-webui
Published Jul 2, 2024
8.4
HIGHCVSS 3.0
EPSS 0.45%
Description
parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_cpp_python-0.2.61+cpuavx2-cp311-cp311-manylinux_2_31_x86_64. The vulnerability arises from the application's 'binding_zoo' feature, which allows attackers to upload and interact with a malicious model file hosted on hugging-face, leading to remote code execution. The issue is linked to a known vulnerability in llama-cpp-python, CVE-2024-34359, which has not been patched in lollms-webui as of commit b454f40a. The vulnerability is exploitable through the application's handling of model files in the 'bindings_zoo' feature, specifically when processing gguf format model files.
Affected products
-
Affected
- ≥ unspecified, ≤ latest
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Parisneo | Parisneo/lollms-Webui | unknown | Affected
|
- < 9.8
-
Affected
- 9.5
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Parisneo | Lollms-Webui | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44465 Advisory
- https://huntr.com/bounties/ecf386df-4b6a-40b2-9000-db0974355acc ExploitIssue TrackingPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44465 | Advisory | |
| https://huntr.com/bounties/ecf386df-4b6a-40b2-9000-db0974355acc | ExploitIssue TrackingPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data