CVE-2024-4841

High PUBLISHED

Path Traversal in parisneo/lollms-webui

parisneo · parisneo/lollms-webui

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
4.0 Medium

At a Glance

A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest. By exploiting this vulnerability, an attacker can predict the folders, subfolders, and files present on the victim's computer. The vulnerability is present in the way the application handles the 'path' parameter in HTTP requests to the '/add_reference_to_local_model' endpoint.

nuclei_scanner
CVE Published
Jun 23, 2024
Exploitation Reported
Jun 23, 2024
CVSS
4.0 Medium
EPSS
Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
parisneo
lollms-webui

9.6 to <= *

Affected
parisneo
parisneo/lollms-webui

unspecified to <= latest

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.