Vulnerability Details CVE-2024-4897
parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_cpp_python-0.2.61+cpuavx2-cp311-cp311-manylinux_2_31_x86_64. The vulnerability arises from the application's 'binding_zoo' feature, which allows attackers to upload and interact with a malicious model file hosted on hugging-face, leading to remote code execution. The issue is linked to a known vulnerability in llama-cpp-python, CVE-2024-34359, which has not been patched in lollms-webui as of commit b454f40a. The vulnerability is exploitable through the application's handling of model files in the 'bindings_zoo' feature, specifically when processing gguf format model files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.4%
CVSS Severity
CVSS v3 Score 8.4
Products affected by CVE-2024-4897
-
cpe:2.3:a:lollms:lollms_web_ui:-
-
cpe:2.3:a:lollms:lollms_web_ui:0.0.1
-
cpe:2.3:a:lollms:lollms_web_ui:0.0.2
-
cpe:2.3:a:lollms:lollms_web_ui:0.0.3
-
cpe:2.3:a:lollms:lollms_web_ui:0.0.4
-
cpe:2.3:a:lollms:lollms_web_ui:0.0.5
-
cpe:2.3:a:lollms:lollms_web_ui:0.0.6
-
cpe:2.3:a:lollms:lollms_web_ui:0.0.7
-
cpe:2.3:a:lollms:lollms_web_ui:0.0.8
-
cpe:2.3:a:lollms:lollms_web_ui:0.0.9
-
cpe:2.3:a:lollms:lollms_web_ui:3.0
-
cpe:2.3:a:lollms:lollms_web_ui:3.5
-
cpe:2.3:a:lollms:lollms_web_ui:4.0
-
cpe:2.3:a:lollms:lollms_web_ui:5.0
-
cpe:2.3:a:lollms:lollms_web_ui:6.0
-
cpe:2.3:a:lollms:lollms_web_ui:6.5
-
cpe:2.3:a:lollms:lollms_web_ui:6.5.0
-
cpe:2.3:a:lollms:lollms_web_ui:6.7
-
cpe:2.3:a:lollms:lollms_web_ui:7.0
-
cpe:2.3:a:lollms:lollms_web_ui:8.0
-
cpe:2.3:a:lollms:lollms_web_ui:8.5
-
cpe:2.3:a:lollms:lollms_web_ui:9.0
-
cpe:2.3:a:lollms:lollms_web_ui:9.1
-
cpe:2.3:a:lollms:lollms_web_ui:9.2
-
cpe:2.3:a:lollms:lollms_web_ui:9.3
-
cpe:2.3:a:lollms:lollms_web_ui:9.4
-
cpe:2.3:a:lollms:lollms_web_ui:9.5
-
cpe:2.3:a:lollms:lollms_web_ui:9.6