PT-2024-38010 · Unknown+1 · Lollms-Webui+1

Published

2024-10-11

·

Updated

2025-07-03

·

CVE-2024-6971

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions lollms-webui (affected versions not specified) lollms (affected versions not specified)
Description A path traversal issue exists in the lollms file system.py file, specifically affecting the functions add rag database, toggle mount rag database, and vectorize folder. These functions lack security measures such as sanitize path from endpoint or sanitize path, allowing an attacker to perform vectorize operations on .sqlite files in any directory on the victim's computer. This could potentially lead to the installation of multiple packages and cause a crash.
Recommendations For lollms-webui, consider disabling the add rag database, toggle mount rag database, and vectorize folder functions until a patch is available. For lollms, consider disabling the add rag database, toggle mount rag database, and vectorize folder functions until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-6971
GHSA-7PGR-32FX-C6X9

Affected Products

Lollms
Lollms-Webui