A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically within the name parameter of the @router.post("/reinstall_extension") route. This vulnerability allows attackers to inject a malicious name parameter, leading to the server loading and executing arbitrary Python files from the upload directory for discussions. This issue arises due to the concatenation of data.name directly with lollmsElfServer.lollms_paths.extensions_zoo_path and its use as an argument for ExtensionBuilder().build_extension(). The server's handling of the __init__.py file in arbitrary locations, facilitated by importlib.machinery.SourceFileLoader, enables the execution of arbitrary code, such as command execution or creating a reverse-shell connection. This vulnerability affects the latest version of parisneo/lollms-webui and can lead to Remote Code Execution (RCE) when the application is exposed to an external endpoint or the UI, especially when bound to 0.0.0.0 or in headless mode. No user interaction is required for exploitation.
CVE-2024-2356
CRITICALNVD 9.69.6—Elevated
EchelonGraph scoreMEDIUM confidence
Score 9.6 from GitHub Security Advisory (severity: CRITICAL) published 2026-02-02. NVD baseline CVSS 9.6; sources differ by 0.0.
Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, nvd
9.6
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
- High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS: 1%CVSS: 9.6Exploit: NoneExposed: 0
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.6
- EG Score
- 9.6(medium)
- EPSS
- 51.7%
- KEV
- Not listed
Published
February 2, 2026
Last Modified
April 15, 2026
Advisory Details (2)
Auto-updated May 21, 2026No patch confirmed yet.
generic
huntr - The world’s first bug bounty platform for AI/ML
https://huntr.com/bounties/cb9867b4-28e3-4406-9031-f66fc28553d4generic
fixed some vulenerabilities · ParisNeo/lollms-webui@41dbb1b · GitHub
https://github.com/parisneo/lollms-webui/commit/41dbb1b3f2e78ea276e5269544e50514252c0c25Frequently asked(5)
What is CVE-2024-2356?
CVE-2024-2356 is a critical vulnerability published on February 2, 2026. A Local File Inclusion (LFI) vulnerability exists in the '/reinstallextension' endpoint of the parisneo/lollms-webui application, specifically within the name parameter of the @router.post("/reinstallextension") route. This vulnerability allows attackers to inject a malicious name parameter,…
When was CVE-2024-2356 disclosed?
CVE-2024-2356 was first published in the National Vulnerability Database on February 2, 2026, with the most recent update on April 15, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2024-2356 actively exploited?
CVE-2024-2356 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 51.7% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
What is the CVSS score of CVE-2024-2356?
CVE-2024-2356 has a CVSS v3 base score of 9.6 (NVD).
How do I remediate CVE-2024-2356?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2024-2356, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2024-2356
Is Your Infrastructure Affected by CVE-2024-2356?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.