Loading HuntDB...

GHSA-rg8g-f4j8-5wgg

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerability allows attackers to perform unauthorized actions by tricking a user into visiting a malicious webpage, which can then trigger arbitrary LoLLMS-XTTS API requests. This issue can lead to the reading and writing of audio files and, when combined with other vulnerabilities, could allow for the reading of arbitrary files on the system and writing files outside the permitted audio file location.

Related CVEs

Key Information

GHSA ID
GHSA-rg8g-f4j8-5wgg
Published
June 24, 2024 3:30 AM
Last Modified
June 24, 2024 3:30 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.