← Vulnerability feed

Vulnerability record · CVE-2024-1520 · published 10 April 2024

CVE-2024-1520: lollms-webui OS command injection in open_code_folder endpoint

Lollms · Lollms Web Ui

The parisneo/lollms-webui application fails to validate the discussion_id parameter in the /open_code_folder endpoint, allowing OS command injection. An unauthenticated network attacker can run arbitrary commands on the host, making this a critical remote code execution flaw.

9.8 CVSS 3.0 Critical EPSS 48% · top 1.2% CWE-78 · OS command injection
9.8CVSS 3.0 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the 'discussion_id' parameter. Attackers can exploit this vulnerability by injecting malicious OS commands, leading to unauthorized command execution on the underlying operating system. This could result in unauthorized access, data leakage, or complete system compromise.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable OS command injection with CVSS 9.8 and high EPSS makes this an urgent patching priority.

What it is

The parisneo/lollms-webui application fails to validate the discussion_id parameter in the /open_code_folder endpoint, allowing OS command injection. An unauthenticated network attacker can run arbitrary commands on the host, making this a critical remote code execution flaw.

Impact

An attacker gains arbitrary command execution on the underlying operating system, enabling unauthorized access, data leakage, or full system compromise.

Attack surface

Reachable over the network via the /open_code_folder endpoint with no authentication or user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The discussion_id parameter carries the injected commands.

Exploitation

Not listed in CISA KEV, but EPSS is 0.48214 (98.8th percentile) and a public exploit reference exists, indicating meaningful exploitation likelihood.

What to do

  • Apply the vendor patch commit 2497d1a4fe5a09f003bf7a9bc426139e9295a934 immediately.
  • Do not expose lollms-webui to untrusted networks; restrict access to localhost or a trusted management network.
  • Add authentication and input validation or allowlisting for the discussion_id parameter.
  • Run the service with least privilege and in a sandboxed or containerized environment to limit command execution impact.

Detection

  • Monitor web logs for requests to /open_code_folder with suspicious characters in discussion_id (;, |, &&, backticks, $()).
  • Alert on unexpected child processes spawned by the lollms-webui service, especially shells or system utilities.
  • Review host process telemetry for command execution originating from the web application user context.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-1520 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-8898Lollms web ui path traversal vulnerabilityA path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerab…EPSS 0.80%9.8CVE-2024-4320Lollms web ui path traversal vulnerabilityA remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within…EPSS 34%9.8CVE-2024-3322Lollms web ui path traversal vulnerabilityA path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5…EPSS 0.73%9.8CVE-2024-2624Lollms web ui path traversal vulnerabilityA path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the `@router.get("/swit…EPSS 1.4%9.8CVE-2024-2359Lollms web ui os command injection vulnerabilityA vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbitrary code. The issu…EPSS 1.2%9.8CVE-2024-2360Lollms web ui path traversal vulnerabilityparisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplie…EPSS 1.9%9.8CVE-2024-5482Lollms web ui server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui application, affecting the lates…EPSS 0.65%9.8CVE-2024-4326Lollms web ui vulnerabilityA vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insuffici…EPSS 0.97%

Source: NIST National Vulnerability Database (record CVE-2024-1520), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.