logo

CVE-2024-4330 lollms

Package

Manager: pip
Name: lollms
Vulnerable Version: =9.6

Severity

Level: Medium

CVSS v3.1: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00094 pctl0.27271

Details

path traversal vulnerability was identified in the parisneo/lollms-webui A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulnerability arises due to improper handling of user-supplied input in the 'list_personalities' endpoint. By crafting a malicious HTTP request, an attacker can traverse the directory structure and view the contents of any folder, albeit limited to subfolder names only. This issue was demonstrated via a specific HTTP request that manipulated the 'category' parameter to access arbitrary directories. The vulnerability is present in the code located at the 'endpoints/lollms_advanced.py' file.

Metadata

Created: 2024-06-02T22:30:25Z
Modified: 2025-07-09T16:53:21Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-9p73-x86v-jw57/GHSA-9p73-x86v-jw57.json
CWE IDs: ["CWE-23"]
Alternative ID: GHSA-9p73-x86v-jw57
Finding: F063
Auto approve: 1