Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8mrm-r7h3-c3hj

Опубликовано: 20 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 7
CVSS3: 7.3

Описание

LoLLMS vulnerable to Expected Behavior Violation

A path traversal vulnerability exists in the apply_settings function of parisneo/lollms versions prior to 9.5.1. The sanitize_path function does not adequately secure the discussion_db_name parameter, allowing attackers to manipulate the path and potentially write to important system folders.

Пакеты

Наименование

lollms

pip
Затронутые версииВерсия исправления

< 9.5.1

9.5.1

EPSS

Процентиль: 29%
0.00107
Низкий

7 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-22
CWE-440

Связанные уязвимости

CVSS3: 7.3
nvd
больше 1 года назад

A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does not adequately secure the `discussion_db_name` parameter, allowing attackers to manipulate the path and potentially write to important system folders.

EPSS

Процентиль: 29%
0.00107
Низкий

7 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-22
CWE-440