Loading HuntDB...

GHSA-3w8h-vhc9-93cj

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' endpoint in the 'lollms_personalities_infos.py' file. This vulnerability allows attackers to read arbitrary files by manipulating the 'category' and 'name' parameters during the 'Copy to custom personas folder for editing' process. By inserting '../' sequences in these parameters, attackers can traverse the directory structure and access files outside of the intended directory. Successful exploitation results in unauthorized access to sensitive information.

Related CVEs

Key Information

GHSA ID
GHSA-3w8h-vhc9-93cj
Published
June 2, 2024 12:30 PM
Last Modified
June 2, 2024 12:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 12, 2025 6:34 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.