Loading HuntDB...

GHSA-482r-2hv2-p3x7

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an attacker can traverse the directory structure and list any directory on the system. This issue affects the latest version of the application. The vulnerability is due to improper handling of user-supplied input in the `list_personalities` function, where the `category` parameter can be controlled to specify arbitrary directories for listing. Successful exploitation of this vulnerability could allow an attacker to list all folders in the drive on the system, potentially leading to information disclosure.

Related CVEs

Key Information

GHSA ID
GHSA-482r-2hv2-p3x7
Published
May 16, 2024 9:33 AM
Last Modified
May 16, 2024 9:33 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.