VYPR

Lollms

by Lollms

pypi: lollms

Source repositories

CVEs (82)

  • CVE-2024-1569HigApr 16, 2024
    risk 0.00cvss 7.5epss 0.01

    parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authentication by sending repeated HTTP POST requests, leading to the opening of…

  • CVE-2024-1522HigMar 30, 2024
    risk 0.00cvss 8.8epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary code on a victim's system. The vulnerability stems from the `/execute_code` API endpoint, which does not properly validate requests, enabling an…

Page 5 of 5