
Remote Code Execution in create_conda_env function in parisneo/lollms
parisneo/lollmsDiscovered by: Syed Jan Muhammad Zaidi
GitHub: dark-ninja10
CVE ID: CVE-2024-3121
Repository Affected: parisneo/lollms
A Remote Code Execution (RCE) vulnerability exists in the create_conda_env function of the lollms framework. This function constructs a system command using unsanitized input, allowing attackers to inject arbitrary commands and gain code execution on the host.
An attacker with access to the env_name input parameter can execute arbitrary OS-level commands. This can result in:
process = subprocess.Popen(f'{conda_path} create --name {env_name} python={python_version} -y', shell=True)
Issue: The env_name variable is directly interpolated into a shell command without input validation or escaping, making it susceptible to shell injection.