Loading HuntDB...

GHSA-jmw2-399f-6mwg

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The vulnerability arises due to inadequate sanitization and validation of model output data, allowing an attacker to inject malicious JavaScript code. This code can be executed within the user's browser context, enabling the attacker to send a request to the `/execute_code` endpoint and establish a reverse shell to the attacker's host. The issue affects various components of the application, including the handling of user input and model output.

Related CVEs

Key Information

GHSA ID
GHSA-jmw2-399f-6mwg
Published
April 10, 2024 6:30 PM
Last Modified
April 10, 2024 6:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.