CVE-2024-2356Disclosure

LOWCVSS 9.6 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically within the `name` parameter of the `@router.post("/reinstall_extension")` route. This vulnerability allows attackers to inject a malicious `name` parameter, leading to the server loading and executing arbitrary Python files from the upload directory for discussions. This issue arises due to the concatenation of `data.name` directly with `lollmsElfServer.lollms_paths.extensions_zoo_path` and its use as an argument for `ExtensionBuilder().build_extension()`. The server's handling of the `__init__.py` file in arbitrary locations, facilitated by `importlib.machinery.SourceFileLoader`, enables the execution of arbitrary code, such as command execution or creating a reverse-shell connection. This vulnerability affects the latest version of parisneo/lollms-webui and can lead to Remote Code Execution (RCE) when the application is exposed to an external endpoint or the UI, especially when bound to `0.0.0.0` or in `headless mode`. No user interaction is required for exploitation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-29

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-02: 2Technical Details · 2026-02-02: 202-02
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2024-2356: CRITICAL] A Local File Inclusion vulnerability in '/reinstall_extension' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary Python files, potentially leading to Remote Code...#cve,CVE-2024-2356,#cybersecurity https://cvefind.com/CVE-2024-2356

    Post summary

    CVE‑2024‑2356 is a critical Local File Inclusion vulnerability in the parisneo/lollms‑webui '/reinstall_extension' endpoint that enables attackers to execute arbitrary Python files, potentially leading to remote code execution. No exploitation, patch, or PoC information is provided.

    0000092
    583 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2024-2356: Remote Code Execution due to LFI ... LFI in lollms-webui's '/reinstall_extension' endpoint leads to trivial RCE via Python file loading - perfect for headles... https://zerodaysignal.com/vulnerability/CVE-2024-2356 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2024‑2356 as a local file inclusion in lollms-webui’s '/reinstall_extension' that enables trivial remote code execution via Python file loading.

    0000098
    132 followersView on X

Explore more