Path Traversal in parisneo/lollms-webui
50Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 4epss 0.7%
from disclosure to weapon
Published on NVDJun 23
VulnCheck+626d
exploitation probability
0.7%top 51% of all CVEs
observed exploitation
yesVulnCheck
A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest. By exploiting this vulnerability, an attacker can predict the folders, subfolders, and files present on the victim's computer. The vulnerability is present in the way the application handles the 'path' parameter in HTTP requests to the '/add_reference_to_local_model' endpoint.
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
parisneo · parisneo/lollms-webui