CVE-2024-7058
CVSS 3.0 Score 4.4 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 23
Summary
CVE-2024-7058 is a newly disclosed vulnerability affecting the sanitize_path function in parisneo/lollms-webui versions 10 and above. An attacker can exploit this issue by utilizing relative paths, such as './', to bypass the intended path sanitization. Consequently, unauthorized access to directories within the personality_folder on the victim's computer becomes possible. This vulnerability poses a potential risk for data breaches and unintended file access. Users are advised to update their installation as soon as a patch is made available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.