Medium severity4.4NVD Advisory· Published Oct 11, 2024· Updated Jun 17, 2026
CVE-2024-6971
CVE-2024-6971
Description
A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the lollms_file_system.py file. The functions add_rag_database, toggle_mount_rag_database, and vectorize_folder do not implement security measures such as sanitize_path_from_endpoint or sanitize_path. This allows an attacker to perform vectorize operations on .sqlite files in any directory on the victim's computer, potentially installing multiple packages and causing a crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lollmsPyPI | <= 9.5.1 | — |
Affected products
3- parisneo/parisneo/lollmsv5Range: unspecified
Patches
Vulnerability mechanics
References
4- huntr.com/bounties/fbfe7cd0-99fb-4305-bd07-8b573364109envdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-7pgr-32fx-c6x9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-6971ghsaADVISORY
- github.com/ParisNeo/lollms/commit/aeace796d861e922133b769710019608a6363264ghsaWEB
News mentions
0No linked articles in our index yet.