Vulnerability Database

296,489

Total vulnerabilities in the database

CVE-2024-6250

An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the open_file endpoint of lollms_advanced.py. The sanitize_path function with allow_absolute_path=True allows an attacker to access arbitrary files and directories on a Windows system. This vulnerability can be exploited to read any file and list arbitrary directories on the affected system.

  • Published: Jun 27, 2024
  • Updated: Jul 10, 2025
  • CVE: CVE-2024-6250
  • Exploit:

No technical information available.

CWEs: