PyPi: Lollms

CVE-2024-6139

Safety vulnerability ID: 78743

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Jun 27, 2024 Updated at Aug 18, 2025
Scan your Python projects for vulnerabilities →

Advisory

Affected versions of the lollms package are vulnerable to Path Traversal due to improper validation of user-provided file paths in the tts_to_file endpoint. The `tts_to_file` endpoint in the XTTS server fails to sanitize path components, allowing directory traversal beyond the intended audio output directory. An attacker can exploit this by providing crafted file paths to cause the lollms package to write audio files to arbitrary locations on the host filesystem and to enumerate directory structure, potentially overwriting files or exposing sensitive system paths.

Affected package

lollms

Latest version: 11.0.0

A python library for AI personality definition

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application