CVE-2024-7058Relative Path Traversal in Lollms

Severity
4.4MEDIUMNVD
EPSS
0.1%
top 83.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20

Description

A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. This can lead to unauthorized access to directories within the personality_folder on the victim's computer.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5parisneo/parisneo_lollmsunspecifiedlatest

🔴Vulnerability Details

1
GHSA
GHSA-v3f4-7pp9-6f99: A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative p2025-03-20

📋Vendor Advisories

1
Red Hat
kernel: ring-buffer: Fix overflow in __rb_map_vma2025-01-11

🕵️Threat Intelligence

1
Bleepingcomputer
SonicWall firewall bug leveraged in attacks after PoC exploit release2025-02-14