PT-2024-38010 · Unknown+1 · Lollms-Webui+1
Published
2024-10-11
·
Updated
2025-07-03
·
CVE-2024-6971
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
lollms-webui (affected versions not specified)
lollms (affected versions not specified)
Description
A path traversal issue exists in the
lollms file system.py file, specifically affecting the functions add rag database, toggle mount rag database, and vectorize folder. These functions lack security measures such as sanitize path from endpoint or sanitize path, allowing an attacker to perform vectorize operations on .sqlite files in any directory on the victim's computer. This could potentially lead to the installation of multiple packages and cause a crash.Recommendations
For lollms-webui, consider disabling the
add rag database, toggle mount rag database, and vectorize folder functions until a patch is available.
For lollms, consider disabling the add rag database, toggle mount rag database, and vectorize folder functions until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lollms
Lollms-Webui