We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sanitization of user input. The issue arises from the lack of path sanitization when handling the `name` parameter in the `unInstall_binding` function, allowing an attacker to traverse directories and execute arbitrary code by loading a malicious `__init__.py` file. This vulnerability affects the latest version of the software. The exploitation of this vulnerability could lead to remote code execution on the system where parisneo/lollms is deployed.
Reserved 2024-04-23 | Published 2024-05-16 | Updated 2024-08-08 | Assigner @huntr_aiCWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
huntr.com/bounties/a55a8c04-df44-49b2-bcfa-2a2b728a299d
github.com/...ommit/7ebe08da7e0026b155af4f7be1d6417bc64cf02f
Support options