CVE-2024-8898
A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which can be exploited to traverse directories outside the intended path.
Vendor
Product
CWE
Yayın Tarihi
2025-03-20 10:15:44
Güncelleme
2025-04-01 20:30:45
Source Identifier
security@huntr.dev
KEV Date Added
-