A path traversal vulnerability exists in the apply_settings
function of parisneo/lollms versions prior to 9.5.1. The sanitize_path
function does not adequately secure the discussion_db_name
parameter, allowing attackers to manipulate the path and potentially write to important system folders.
{ "nvd_published_at": "2024-07-20T04:15:05Z", "cwe_ids": [ "CWE-440" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-09-13T19:34:25Z" }