Loading HuntDB...

GHSA-w9qf-83jg-2x6c

GitHub Security Advisory

lollms vulnerable to dot-dot-slash path traversal in XTTS server

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of user-provided file paths in the `tts_to_file` endpoint.

Affected Packages

PyPI lollms
Affected versions: 0 (last affected: 9.5.1)

Related CVEs

Key Information

GHSA ID
GHSA-w9qf-83jg-2x6c
Published
June 27, 2024 9:32 PM
Last Modified
June 28, 2024 9:10 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
lollms
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 7, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.