CVE-2024-5824High· 7.4▾ Twilightlollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.4%
A path traversal vulnerability in the /set_personality_config endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the configs/config.yaml file. This can lead to remote code execution by changing server configuration properties such as force_accept_remote_access and turn_on_code_validation.
lollms < 9.5.0Upgrade to a patched release:
lollms 9.5.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-4078Critical· 9.8LoLLMS Command Injection vulnerability
CVE-2026-1114Critical· 9.8LoLLMs is vulnerable to Improper Access Control through weak secret key
CVE-2024-6281High· 7.3LoLLMS vulnerable to Expected Behavior Violation
CVE-2026-1117High· 8.2Lollms has an Improper Access Control vulnerability
CVE-2024-3429Critical· 9.8LoLLMS Path Traversal vulnerability
CVE-2026-1116Medium· 6.1A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms pr…