PT-2024-38022 · Unknown · Parisneo/Lollms-Webui+1

Published

2024-10-11

·

Updated

2024-11-15

·

CVE-2024-6985

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions parisneo/lollms-webui (affected versions not specified) parisneo/lollms (affected versions not specified)
Description A path traversal issue exists due to improper sanitization of the personality folder parameter in the "api open personality folder" endpoint. This allows an attacker to read any folder in the personality folder on the victim's computer and access arbitrary files, despite sanitize path being set.
Recommendations For parisneo/lollms-webui, as a temporary workaround, consider restricting access to the "api open personality folder" endpoint until a patch is available. For parisneo/lollms, avoid using the personality folder parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2024-6985
GHSA-6H64-G7CJ-HJ56
PYSEC-2024-122

Affected Products

Parisneo/Lollms
Parisneo/Lollms-Webui