CVE-2024-1522

    Dashboard / Vulnerabilities / CVE-2024-1522

    CVE-2024-1522

    Published: 30 Mar 2024Last Modified: 12 Aug 2026

    Summary: Cross-Site Request Forgery (CSRF) Leading to Remote Code Execution in parisneo/lollms-webui

    Details: A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate requests, enabling an attacker to craft a malicious webpage that, when visited by a victim, submits a form to the victim's local lollms-webui instance to execute arbitrary OS commands. This issue allows attackers to take full control of the victim's system without requiring direct network access to the vulnerable application.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 80d72ca433cf0cb8318e0d08fa774b608aa29f05

    Affected versions

    v9.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2024-1522 | CVE-DB