Security Advisory

CVE-2024-8898

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-20 10:10:58
Last updated 2025-03-20 16:20:06
Assigner @huntr_ai
State PUBLISHED

Description

A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which can be exploited to traverse directories outside the intended path.