Security Advisory

CVE-2024-7058

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-20 10:09:45
Last updated 2025-03-20 18:35:07
Assigner @huntr_ai
State PUBLISHED

Description

A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as ./. This can lead to unauthorized access to directories within the personality_folder on the victims computer.