PT-2025-12248 · Unknown · Parisneo/Lollms-Webui
Published
2025-03-20
·
Updated
2025-03-20
·
CVE-2024-8898
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
parisneo/lollms-webui version V12 (Strawberry)
Description
A path traversal issue exists in the API endpoints for installation and uninstallation. This allows attackers to create or delete directories with arbitrary paths on the system. The problem arises due to insufficient sanitization of user-supplied input, which can be exploited to navigate directories outside the intended path. The
install and uninstall API endpoints are specifically affected.Recommendations
For parisneo/lollms-webui version V12 (Strawberry), consider disabling the
install and uninstall API endpoints until a patch is available to prevent exploitation of the path traversal vulnerability. Restrict access to these endpoints to minimize the risk of directory creation or deletion with arbitrary paths.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Parisneo/Lollms-Webui