Security Advisory
CVE-2024-7058
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as ./. This can lead to unauthorized access to directories within the personality_folder on the victims computer.