Skip to main content
CRITICAL

CVE-2024-4267

CVSS v3

9.8

CRITICAL

EPSS Score

1.7 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper neutralization of special elements used in a command within the 'open_file' function. An attacker can exploit this vulnerability by crafting a malicious file path that, when processed by the 'open_file' function, executes arbitrary system commands or reads sensitive file content. This issue is present in the code where

Technical details

CVSS v3 Vector
3.1
Published
2024-05-22
Last Modified
2025-08-15

Frequently asked questions

What is CVE-2024-4267?

A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper neutralization of special elements used in a command within the 'open_file' function. An attacker can exploit this vulnerability by crafting a malicious file path that, when processed by the 'open_file' function, executes arbitrary system commands or reads sensitive file content. This issue is present in the code where

Is CVE-2024-4267 actively exploited?

Active exploitation of CVE-2024-4267 has not been confirmed. The EPSS score is 1.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2024-4267?

CVE-2024-4267 has a CVSS v3 base score of 9.8 (CRITICAL severity), with vector string 3.1.

Is CVE-2024-4267 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key