Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-9p73-x86v-jw57: path traversal vulnerability was identified in the parisneo/lollms-webui

A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulnerability arises due to improper handling of user-supplied input in the ‘list_personalities’ endpoint. By crafting a malicious HTTP request, an attacker can traverse the directory structure and view the contents of any folder, albeit limited to subfolder names only. This issue was demonstrated via a specific HTTP request that manipulated the ‘category’ parameter to access arbitrary directories. The vulnerability is present in the code located at the ‘endpoints/lollms_advanced.py’ file.

ghsa
#vulnerability#web#git

Skip to content

Navigation Menu

    • Actions

      Automate any workflow

    • Packages

      Host and manage packages

    • Security

      Find and fix vulnerabilities

    • Codespaces

      Instant dev environments

    • Copilot

      Write better code with AI

    • Code review

      Manage code changes

    • Issues

      Plan and track work

    • Discussions

      Collaborate outside of code

    • GitHub Sponsors

      Fund open source developers

*   The ReadME Project
    
    GitHub community articles
    • Enterprise platform

      AI-powered developer platform

  • Pricing

Provide feedback

Saved searches****Use saved searches to filter your results more quickly

Sign up

  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2024-4330

path traversal vulnerability was identified in the parisneo/lollms-webui

Moderate severity GitHub Reviewed Published Jun 2, 2024 to the GitHub Advisory Database • Updated Jun 2, 2024

Description

A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulnerability arises due to improper handling of user-supplied input in the ‘list_personalities’ endpoint. By crafting a malicious HTTP request, an attacker can traverse the directory structure and view the contents of any folder, albeit limited to subfolder names only. This issue was demonstrated via a specific HTTP request that manipulated the ‘category’ parameter to access arbitrary directories. The vulnerability is present in the code located at the ‘endpoints/lollms_advanced.py’ file.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-4330
  • ParisNeo/lollms@0e52d59
  • https://huntr.com/bounties/154a78d5-3960-4fc6-8666-f982b5e70ed7

Published to the GitHub Advisory Database

Jun 2, 2024

ghsa: Latest News

GHSA-c9p4-xwr9-rfhx: Zot IdP group membership revocation ignored