CVE-2024-6281High· 7.3▾ TwilightLoLLMS vulnerable to Expected Behavior Violation
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
A path traversal vulnerability exists in the apply_settings function of parisneo/lollms versions prior to 9.5.1. The sanitize_path function does not adequately secure the discussion_db_name parameter, allowing attackers to manipulate the path and potentially write to important system folders.
lollms < 9.5.1Upgrade to a patched release:
lollms 9.5.1Connected by shared product, vendor, weakness, or advisory.
CVE-2024-4078Critical· 9.8LoLLMS Command Injection vulnerability
CVE-2024-5824High· 7.4lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE
CVE-2026-1114Critical· 9.8LoLLMs is vulnerable to Improper Access Control through weak secret key
CVE-2026-1117High· 8.2Lollms has an Improper Access Control vulnerability
CVE-2024-3429Critical· 9.8LoLLMS Path Traversal vulnerability
CVE-2026-1116Medium· 6.1A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms pr…