MEDIUM
Path Traversal in api open_personality_folder in parisneo/lollms-webui
Published Oct 11, 2024
6.9
MEDIUMCVSS 4.0
EPSS 0.36%
Description
A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnerability allows an attacker to read any folder in the personality_folder on the victim's computer, even though sanitize_path is set. The issue arises due to improper sanitization of the personality_folder parameter, which can be exploited to traverse directories and access arbitrary files.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<5.9.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Parisneo | Parisneo/lollms | n/a |
|
-
- Version 0StatusaffectedConstraints<5.9.0
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/advisories/GHSA-6h64-g7cj-hj56 Advisory
- https://github.com/parisneo/lollms/commit/28ee567a9a120967215ff19b96ab7515ce469620 Patch
- https://huntr.com/bounties/79c11579-47d8-4e68-8466-b47c3bf5ef6a ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6985
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-6h64-g7cj-hj56 | Advisory | |
| https://github.com/parisneo/lollms/commit/28ee567a9a120967215ff19b96ab7515ce469620 | Patch | |
| https://huntr.com/bounties/79c11579-47d8-4e68-8466-b47c3bf5ef6a | ExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-6985 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Oct 11, 2024
Updated Oct 11, 2024
Reserved Jul 22, 2024
Link CVE-2024-6985
CISA Vulnrichment
GHSA-6H64-G7CJ-HJ56 Updated Oct 11, 2024