Launch Week Day 1: Announcing Security Design Review
HIGH 7.3 PyPI

LoLLMS vulnerable to Expected Behavior Violation

GHSA-8mrm-r7h3-c3hj · CVE-2024-6281

Published · Modified

Description

A path traversal vulnerability exists in the apply_settings function of parisneo/lollms versions prior to 9.5.1. The sanitize_path function does not adequately secure the discussion_db_name parameter, allowing attackers to manipulate the path and potentially write to important system folders.

Ready to move

Start Securing

Free, no credit card | First findings in minutes