{"id":"CVE-2024-4330","aliases":["GHSA-9p73-x86v-jw57","PYSEC-2026-1589"],"title":"path traversal vulnerability was identified in the parisneo/lollms-webui ","summary":"path traversal vulnerability was identified in the parisneo/lollms-webui ","severity":"medium","cvss":4,"cvssVector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","vendor":"lollms","product":"lollms","ecosystem":"pip","affected":["lollms"],"published":"2024-06-02","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-9p73-x86v-jw57","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-4330"},{"url":"https://github.com/ParisNeo/lollms/commit/0e52d59a06b7f05e3b2611ce7b053fafa44143a9"},{"url":"https://github.com/ParisNeo/lollms"},{"url":"https://huntr.com/bounties/154a78d5-3960-4fc6-8666-f982b5e70ed7"}],"tags":["osv","pip"],"epss":0.00285,"epssPercentile":0.21237,"ingestedAt":"2026-07-08T18:25:48.052Z","slug":"CVE-2024-4330","body":"## Overview\n\nA path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulnerability arises due to improper handling of user-supplied input in the 'list_personalities' endpoint. By crafting a malicious HTTP request, an attacker can traverse the directory structure and view the contents of any folder, albeit limited to subfolder names only. This issue was demonstrated via a specific HTTP request that manipulated the 'category' parameter to access arbitrary directories. The vulnerability is present in the code located at the 'endpoints/lollms_advanced.py' file.\n\n## Affected packages\n\n- `lollms`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":22,"depthScoreParts":{"impact":22,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}