Launch Week Day 1: Announcing Security Design Review
LOW 3.4 PyPI

Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py

GHSA-7pgr-32fx-c6x9 · CVE-2024-6971

Published · Modified

Description

A path traversal vulnerability exists in the ParisNeo/lollms repository, specifically in the lollms_file_system.py file. The functions add_rag_database, toggle_mount_rag_database, and vectorize_folder do not implement security measures such as sanitize_path_from_endpoint or sanitize_path. This allows an attacker to perform vectorize operations on .sqlite files in any directory on the victim's computer, potentially installing multiple packages and causing a crash.

Ready to move

Start Securing

Free, no credit card | First findings in minutes