CVE-2024-8898: Path Traversal in parisneo/lollms-webui
A path traversal vulnerability exists in the install and uninstall API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which can be exploited to traverse directories outside the intended path.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8898?
CVE-2024-8898 is considered a critical vulnerability due to the potential for arbitrary file system modifications.
How do I fix CVE-2024-8898?
To mitigate CVE-2024-8898, update to the latest version of parisneo/lollms-webui where the path traversal issue has been resolved.
What impact does CVE-2024-8898 have on my system?
CVE-2024-8898 allows attackers to create or delete arbitrary directories, which can lead to severe data loss and system compromise.
Which versions of lollms-webui are affected by CVE-2024-8898?
CVE-2024-8898 affects the lollms-webui version V12 (Strawberry) and possibly earlier versions.
Where can I find more information about CVE-2024-8898?
More information regarding CVE-2024-8898 can typically be found in security advisories from the vendor or trusted cybersecurity resources.