Path Traversal Vulnerability in Lollms-Webui Affects Versions Up to 9.5
CVE-2024-3322
What is CVE-2024-3322?
A path traversal vulnerability has been identified in the native personality 'codeguard' of the parisneo/lollms-webui, affecting all versions up to 9.5. This vulnerability arises from the inadequate restriction of user-supplied input to the 'process_folder' function defined in processor.py. The flaw enables an attacker to bypass directory limitations by using '../' or absolute paths, which exposes the application to arbitrary file read and overwrite actions. Consequently, this can result in the unauthorized disclosure of sensitive information and manipulation of files in the specified directories, representing a critical security issue for users of the product.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
parisneo/lollms-webui < 9.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
