{"id":"CVE-2024-4315","aliases":["PYSEC-2026-403"],"url":"https://o3.security/vulnerability/CVE-2024-4315","summary":"parisneo/lollms Local File Inclusion (LFI) attack","details":"parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoint` function fails to properly sanitize Windows-style paths (backward slash `\\`), allowing attackers to perform directory traversal attacks on Windows systems. This vulnerability can be exploited through various routes, including `personalities` and `/del_preset`, to read or delete any file on the Windows filesystem, compromising the system's availability.","published":"2024-06-12T03:31:15Z","modified":"2026-06-29T12:26:43.133364224Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"lollms","fixedVersion":"9.5.0"}],"fix":{"url":"https://github.com/parisneo/lollms/commit/95ad36eeffc6a6be3e3f35ed35a384d768f0ecf6","label":"parisneo/lollms@95ad36e"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-4315"},{"type":"WEB","url":"https://github.com/parisneo/lollms/commit/95ad36eeffc6a6be3e3f35ed35a384d768f0ecf6"},{"type":"PACKAGE","url":"https://github.com/ParisNeo/lollms"},{"type":"WEB","url":"https://huntr.com/bounties/8a1b0197-2c36-4276-b92b-630a2a9bb09c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-29T12:26:43.133364224Z"}}