High severity8.4NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-9919
CVE-2024-9919
Description
A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- huntr.com/bounties/5c00f56b-32a8-4e26-a4e3-de64f139da6bnvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.