lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE
High severity
GitHub Reviewed
Published
Jun 27, 2024
to the GitHub Advisory Database
•
Updated Jun 28, 2024
Description
Published by the National Vulnerability Database
Jun 27, 2024
Published to the GitHub Advisory Database
Jun 27, 2024
Reviewed
Jun 28, 2024
Last updated
Jun 28, 2024
A path traversal vulnerability in the
/set_personality_config
endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite theconfigs/config.yaml
file. This can lead to remote code execution by changing server configuration properties such asforce_accept_remote_access
andturn_on_code_validation
.References