{"id":"CVE-2024-6982","aliases":["PYSEC-2026-1591"],"url":"https://o3.security/vulnerability/CVE-2024-6982","summary":"LoLLMS Code Injection vulnerability","details":"A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability arises from the use of Python's `eval()` function to evaluate mathematical expressions within a Python sandbox that disables `__builtins__` and only allows functions from the `math` module. This sandbox can be bypassed by loading the `os` module using the `_frozen_importlib.BuiltinImporter` class, allowing an attacker to execute arbitrary commands on the server. The issue is fixed in version 9.10.","published":"2025-03-20T12:32:45Z","modified":"2026-07-07T17:56:33.515525406Z","cvss":{"score":8.4,"severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"lollms","fixedVersion":"11.0.0"}],"fix":{"url":"https://github.com/parisneo/lollms/commit/30e7eaba2ccfb751a81e7cb29fdef2ae8ffa6832","label":"parisneo/lollms@30e7eab"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6982"},{"type":"WEB","url":"https://github.com/parisneo/lollms/commit/30e7eaba2ccfb751a81e7cb29fdef2ae8ffa6832"},{"type":"PACKAGE","url":"https://github.com/ParisNeo/lollms"},{"type":"WEB","url":"https://huntr.com/bounties/4f8e73ac-aaaf-4d5c-a6dd-58215b5a7fea"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:56:33.515525406Z"}}