Medium severity6.7NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-10019
CVE-2024-10019
Description
A vulnerability in the start_app_server function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The function does not properly sanitize the app_name parameter, enabling an attacker to upload a malicious server.py file and execute arbitrary code by exploiting the path traversal vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- huntr.com/bounties/3cf80890-2d8a-4fc7-8e0e-6d4bf648b3eanvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.