A Path Traversal vulnerability exists in the parisneo...
Moderate severity
Unreviewed
Published
Jun 23, 2024
to the GitHub Advisory Database
•
Updated Jun 23, 2024
Description
Published by the National Vulnerability Database
Jun 23, 2024
Published to the GitHub Advisory Database
Jun 23, 2024
Last updated
Jun 23, 2024
A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest. By exploiting this vulnerability, an attacker can predict the folders, subfolders, and files present on the victim's computer. The vulnerability is present in the way the application handles the 'path' parameter in HTTP requests to the '/add_reference_to_local_model' endpoint.
References