Path Traversal Vulnerability in Lollms Web UI by Parisneo
CVE-2024-8898

9.8CRITICAL

Key Information:

Vendor
Parisneo
Vendor
CVE Published:
20 March 2025

Summary

A path traversal vulnerability has been identified in the install and uninstall API endpoints of the Lollms Web UI by Parisneo. This flaw permits attackers to create or remove directories using arbitrary paths within the system. The root of the issue lies in the inadequate sanitization of user input, allowing for exploitation that grants unauthorized access to directories outside of the intended file structure. Active measures should be taken to patch this vulnerability to safeguard against potential exploitation.

Affected Version(s)

parisneo/lollms-webui < unspecified

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.