Safety vulnerability ID: 78731
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of the lollms package are vulnerable to Path Traversal due to improper handling of user-supplied input in the `list_personalities` endpoint. The `endpoints/lollms_advanced.py` component fails to sanitize the `category` parameter, allowing attackers to manipulate directory traversal sequences to access arbitrary directories. A remote attacker can exploit this by sending a crafted HTTP request to the `list_personalities` endpoint with a malicious `category` value, enabling viewing of subfolder names across the file system and compromising confidentiality.
Latest version: 11.0.0
A python library for AI personality definition
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application