Back

HIGH

Path Traversal in parisneo/lollms

Published Jul 20, 2024

Description

A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does not adequately secure the `discussion_db_name` parameter, allowing attackers to manipulate the path and potentially write to important system folders.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Jul 20, 2024
Updated Oct 15, 2025
Reserved Jun 23, 2024
CISA Vulnrichment
Updated Jul 23, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-8MRM-R7H3-C3HJ