Remote Code Execution in Calculate Function in parisneo/lollms
Published Mar 20, 2025
8.4
HIGHCVSS 3.0
EPSS 0.46%
Description
A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability arises from the use of Python's `eval()` function to evaluate mathematical expressions within a Python sandbox that disables `__builtins__` and only allows functions from the `math` module. This sandbox can be bypassed by loading the `os` module using the `_frozen_importlib.BuiltinImporter` class, allowing an attacker to execute arbitrary commands on the server. The issue is fixed in version 9.10.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<9.10
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Parisneo | Parisneo/lollms | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-6967 Advisory
- https://github.com/advisories/GHSA-jccx-m9v4-9hwh Advisory
- https://github.com/parisneo/lollms/commit/30e7eaba2ccfb751a81e7cb29fdef2ae8ffa6832
- https://huntr.com/bounties/4f8e73ac-aaaf-4d5c-a6dd-58215b5a7fea
- https://nvd.nist.gov/vuln/detail/CVE-2024-6982
Change history (0)
No recorded changes yet.