CVE-2024-4330Medium· 4.0▾ Sunlitpath traversal vulnerability was identified in the parisneo/lollms-webui
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulnerability arises due to improper handling of user-supplied input in the 'list_personalities' endpoint. By crafting a malicious HTTP request, an attacker can traverse the directory structure and view the contents of any folder, albeit limited to subfolder names only. This issue was demonstrated via a specific HTTP request that manipulated the 'category' parameter to access arbitrary directories. The vulnerability is present in the code located at the 'endpoints/lollms_advanced.py' file.
lollmsRefer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-1163Medium· 4.1parisneo/lollms has an insufficient session expiration vulnerability
CVE-2024-6139High· 7.3lollms vulnerable to dot-dot-slash path traversal in XTTS server
CVE-2024-6982High· 8.4LoLLMS Code Injection vulnerability
CVE-2025-6386High· 7.5Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
CVE-2024-6085High· 8.6lollms vulnerable to path traversal due to unauthenticated root folder settings change
CVE-2024-6971Low· 3.4Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py