A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which can be exploited to traverse directories outside the intended path.
References
Configurations
History
No history.
Information
Published : 2025-03-20 10:15
Updated : 2025-04-01 20:30
NVD link : CVE-2024-8898
Mitre link : CVE-2024-8898
CVE.ORG link : CVE-2024-8898
JSON object : View
Products Affected
lollms
- lollms_web_ui
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
