PT-2025-12248 · Unknown · Parisneo/Lollms-Webui

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-8898

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions parisneo/lollms-webui version V12 (Strawberry)
Description A path traversal issue exists in the API endpoints for installation and uninstallation. This allows attackers to create or delete directories with arbitrary paths on the system. The problem arises due to insufficient sanitization of user-supplied input, which can be exploited to navigate directories outside the intended path. The install and uninstall API endpoints are specifically affected.
Recommendations For parisneo/lollms-webui version V12 (Strawberry), consider disabling the install and uninstall API endpoints until a patch is available to prevent exploitation of the path traversal vulnerability. Restrict access to these endpoints to minimize the risk of directory creation or deletion with arbitrary paths.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8898

Affected Products

Parisneo/Lollms-Webui