CVE-2024-6982
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
20/03/2025
Last modified:
20/03/2025
Description
A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability arises from the use of Python's `eval()` function to evaluate mathematical expressions within a Python sandbox that disables `__builtins__` and only allows functions from the `math` module. This sandbox can be bypassed by loading the `os` module using the `_frozen_importlib.BuiltinImporter` class, allowing an attacker to execute arbitrary commands on the server. The issue is fixed in version 9.10.
Impact
Base Score 3.x
8.40
Severity 3.x
HIGH