← Vulnerability feed

Vulnerability record · CVE-2024-5482 · published 6 June 2024

CVE-2024-5482: Lollms web ui server-side request forgery (ssrf) vulnerability

Lollms · Lollms Web Ui

A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui application, affecting the latest version. The vulnerability arises because the application does not adequately validate URLs entered by users, allowing them to input arbitrary URLs, including those that target internal resources such as 'localhost' or '127.0.0.1'. This flaw enables attackers to make unauthorized requests to internal or external systems, potentially leading to access to sensitive data, service disruption, network integrity compromise, business logic manipulation, and abuse of third-party resources. The issue is critical and requires immediate attention to maintain the application's security and integrity.

9.8 CVSS 3.1 Critical EPSS 0.65% · top 50.9% CWE-918 · Server-side request forgery (SSRF)
9.8CVSS 3.1 base score
0.65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui application, affecting the latest version. The vulnerability arises because the application does not adequately validate URLs entered by users, allowing them to input arbitrary URLs, including those that target internal resources such as 'localhost' or '127.0.0.1'. This flaw enables attackers to make unauthorized requests to internal or external systems, potentially leading to access to sensitive data, service disruption, network integrity compromise, business logic manipulation, and abuse of third-party resources. The issue is critical and requires immediate attention to maintain the application's security and integrity.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-5482 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-8898Lollms web ui path traversal vulnerabilityA path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerab…EPSS 0.80%9.8CVE-2024-4320Lollms web ui path traversal vulnerabilityA remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within…EPSS 34%9.8CVE-2024-3322Lollms web ui path traversal vulnerabilityA path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5…EPSS 0.73%9.8CVE-2024-2624Lollms web ui path traversal vulnerabilityA path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the `@router.get("/swit…EPSS 1.4%9.8CVE-2024-2359Lollms web ui os command injection vulnerabilityA vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbitrary code. The issu…EPSS 1.2%9.8CVE-2024-2360Lollms web ui path traversal vulnerabilityparisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplie…EPSS 1.9%9.8CVE-2024-4326Lollms web ui vulnerabilityA vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insuffici…EPSS 0.97%9.8CVE-2024-2358Lollms web ui vulnerabilityA path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerabili…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2024-5482), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.