{"id":"CVE-2024-1522","summary":"Cross-Site Request Forgery (CSRF) Leading to Remote Code Execution in parisneo/lollms-webui","details":"A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate requests, enabling an attacker to craft a malicious webpage that, when visited by a victim, submits a form to the victim's local lollms-webui instance to execute arbitrary OS commands. This issue allows attackers to take full control of the victim's system without requiring direct network access to the vulnerable application.","modified":"2026-08-12T03:51:25.739876376Z","published":"2024-03-30T18:02:59.260Z","database_specific":{"cna_assigner":"@huntr_ai","cwe_ids":["CWE-352"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1522.json"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/687cef92-3432-4d6c-af92-868eccabbb71"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1522.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1522"},{"type":"FIX","url":"https://github.com/parisneo/lollms-webui/commit/0b51063119cfb5e391925d232a4af1de9dc32e2b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/parisneo/lollms-webui","events":[{"introduced":"80d72ca433cf0cb8318e0d08fa774b608aa29f05"},{"fixed":"0b51063119cfb5e391925d232a4af1de9dc32e2b"}],"database_specific":{"cpe":"cpe:2.3:a:lollms:lollms_web_ui:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"9.0"},{"last_affected":"9.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-1522.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}