A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which can be exploited to traverse directories outside the intended path.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which can be exploited to traverse directories outside the intended path. | |
Title | Path Traversal in parisneo/lollms-webui | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:10:58.125Z
Updated: 2025-03-20T16:20:06.356Z
Reserved: 2024-09-16T18:03:42.402Z
Link: CVE-2024-8898

Updated: 2025-03-20T16:19:56.882Z

Status : Awaiting Analysis
Published: 2025-03-20T10:15:44.590
Modified: 2025-03-20T17:15:37.863
Link: CVE-2024-8898

No data.