296,489
Total vulnerabilities in the database
A vulnerability in the start_app_server
function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The function does not properly sanitize the app_name
parameter, enabling an attacker to upload a malicious server.py
file and execute arbitrary code by exploiting the path traversal vulnerability.
Software | From | Fixed in |
---|---|---|
lollms / lollms_web_ui | 12 | 12.x |