CVE-2024-6971 Information
Nov 01, 2024
cve
Description
A path traversal vulnerability exists in the parisneo/lollms-webui repository specifically in the lollms_file_system.py file. The functions add_rag_database toggle_mount_rag_database and vectorize_folder do not implement security measures such as sanitize_path_from_endpoint or sanitize_path. This allows an attacker to perform vectorize operations on .sqlite files in any directory on the victim’s computer potentially installing multiple packages and causing a crash.
Reference
https://huntr.com/bounties/fbfe7cd0-99fb-4305-bd07-8b573364109e
Share on: