High severity8.8NVD Advisory· Published Mar 30, 2024· Updated Jun 17, 2026
CVE-2024-1522
CVE-2024-1522
Description
A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the /execute_code API endpoint, which does not properly validate requests, enabling an attacker to craft a malicious webpage that, when visited by a victim, submits a form to the victim's local lollms-webui instance to execute arbitrary OS commands. This issue allows attackers to take full control of the victim's system without requiring direct network access to the vulnerable application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/parisneo/lollms-webui/commit/0b51063119cfb5e391925d232a4af1de9dc32e2bnvdPatch
- huntr.com/bounties/687cef92-3432-4d6c-af92-868eccabbb71nvdExploitIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.