Low severity3.3NVD Advisory· Published Jun 24, 2024· Updated Jun 17, 2026
CVE-2024-3121
CVE-2024-3121
Description
A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0. The vulnerability arises from the use of shell=True in the subprocess.Popen function, which allows an attacker to inject arbitrary commands by manipulating the env_name and python_version parameters. This issue could lead to a serious security breach as demonstrated by the ability to execute the 'whoami' command among potentially other harmful commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lollmsPyPI | <= 9.5.1 | — |
Affected products
3- parisneo/parisneo/lollmsv5Range: unspecified
Patches
Vulnerability mechanics
References
3- huntr.com/bounties/db57c343-9b80-4c1c-9ab0-9eef92c9b27bnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-79h8-gxhq-q3jgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-3121ghsaADVISORY
News mentions
0No linked articles in our index yet.