CVE-2024-7058

CVSS 3.0 Score 4.4 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 23

Summary

CVE-2024-7058 is a newly disclosed vulnerability affecting the sanitize_path function in parisneo/lollms-webui versions 10 and above. An attacker can exploit this issue by utilizing relative paths, such as './', to bypass the intended path sanitization. Consequently, unauthorized access to directories within the personality_folder on the victim's computer becomes possible. This vulnerability poses a potential risk for data breaches and unintended file access. Users are advised to update their installation as soon as a patch is made available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share