CVE-2024-8581

CVSS 3.0 Score 9.1 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 94

Summary

CVE-2024-8581 is a newly disclosed vulnerability affecting version V12 (Strawberry) of the `parisneo/lollms-webui` application. This issue resides in the `upload_app` function, which fails to filter user input on the `filename` value. As a result, an attacker can exploit this Path Traversal error to delete any file or directory on the targeted system. This vulnerability poses a significant risk, as it allows unauthorized modification or deletion of critical system files. System administrators are strongly advised to upgrade to a patched version of `parisneo/lollms-webui` to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share