296,489
Total vulnerabilities in the database
An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the open_file
endpoint of lollms_advanced.py
. The sanitize_path
function with allow_absolute_path=True
allows an attacker to access arbitrary files and directories on a Windows system. This vulnerability can be exploited to read any file and list arbitrary directories on the affected system.
Software | From | Fixed in |
---|---|---|
lollms / lollms_web_ui | 9.6 | 9.6.x |