Low severity3.3NVD Advisory· Published Jun 23, 2024· Updated Jun 17, 2026
CVE-2024-4841
CVE-2024-4841
Description
A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest. By exploiting this vulnerability, an attacker can predict the folders, subfolders, and files present on the victim's computer. The vulnerability is present in the way the application handles the 'path' parameter in HTTP requests to the '/add_reference_to_local_model' endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- huntr.com/bounties/740dda3e-7104-4ccf-9ac4-8870e4d6d602nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.