{"id":"CVE-2024-3121","aliases":["PYSEC-2026-1584"],"url":"https://o3.security/vulnerability/CVE-2024-3121","summary":"Remote Code Execution in create_conda_env function in lollms","details":"A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository. The vulnerability arises from the use of shell=True in the subprocess.Popen function, which allows an attacker to inject arbitrary commands by manipulating the env_name and python_version parameters. This issue could lead to a serious security breach as demonstrated by the ability to execute the 'whoami' command among potentially other harmful commands.","published":"2024-06-24T00:34:02Z","modified":"2026-07-07T17:56:50.302002852Z","cvss":{"score":6.8,"severity":"MEDIUM","vector":"CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"lollms","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-3121"},{"type":"PACKAGE","url":"https://github.com/ParisNeo/lollms"},{"type":"WEB","url":"https://huntr.com/bounties/db57c343-9b80-4c1c-9ab0-9eef92c9b27b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:56:50.302002852Z"}}