CVE-2024-6971Low· 3.4▾ SunlitLord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.3%
A path traversal vulnerability exists in the ParisNeo/lollms repository, specifically in the lollms_file_system.py file. The functions add_rag_database, toggle_mount_rag_database, and vectorize_folder do not implement security measures such as sanitize_path_from_endpoint or sanitize_path. This allows an attacker to perform vectorize operations on .sqlite files in any directory on the victim's computer, potentially installing multiple packages and causing a crash.
lollms <= 9.5.1Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-1163Medium· 4.1parisneo/lollms has an insufficient session expiration vulnerability
CVE-2024-6139High· 7.3lollms vulnerable to dot-dot-slash path traversal in XTTS server
CVE-2024-6982High· 8.4LoLLMS Code Injection vulnerability
CVE-2025-6386High· 7.5Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
CVE-2024-4330Medium· 4.0path traversal vulnerability was identified in the parisneo/lollms-webui
CVE-2024-6085High· 8.6lollms vulnerable to path traversal due to unauthenticated root folder settings change