# CVE-2024-4326

## Summary

- **CVE ID:** CVE-2024-4326
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-15
- **Published:** May 16, 2024
- **Last Modified:** Mar 13, 2026

## Description

A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypass protections by setting the host to localhost, enabling code execution, and disabling code validation through the `/apply_settings` endpoint. Subsequently, arbitrary commands can be executed remotely via the `/execute_code` endpoint, exploiting the delay in settings enforcement. This issue was addressed in version 9.5.

## Affected Products

- parisneo — parisneo/lollms-webui (unspecified)

## References

- [CNA](https://huntr.com/bounties/2ab9f03d-0538-4317-be21-0748a079cbdd)
- [CNA](https://github.com/parisneo/lollms-webui/commit/abb4c6d495a95a3ef5b114ffc57f85cd650b905e)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.97%
- **EPSS Percentile:** 59.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._