{"id":"CVE-2024-6985","aliases":["PYSEC-2024-122"],"url":"https://o3.security/vulnerability/CVE-2024-6985","summary":"Lord of Large Language Models (LoLLMs)  path traversal vulnerability in the api open_personality_folder endpoint","details":"A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms. This vulnerability allows an attacker to read any folder in the personality_folder on the victim's computer, even though sanitize_path is set. The issue arises due to improper sanitization of the personality_folder parameter, which can be exploited to traverse directories and access arbitrary files.","published":"2024-10-11T18:32:50Z","modified":"2024-11-15T20:57:13.953338Z","cvss":{"score":4.4,"severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"lollms","fixedVersion":null}],"fix":{"url":"https://github.com/parisneo/lollms/commit/28ee567a9a120967215ff19b96ab7515ce469620","label":"parisneo/lollms@28ee567"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6985"},{"type":"WEB","url":"https://github.com/parisneo/lollms/commit/28ee567a9a120967215ff19b96ab7515ce469620"},{"type":"PACKAGE","url":"https://github.com/ParisNeo/lollms"},{"type":"WEB","url":"https://huntr.com/bounties/79c11579-47d8-4e68-8466-b47c3bf5ef6a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-15T20:57:13.953338Z"}}