CVE-2024-8898

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 20, 2025
Updated: Apr 1, 2025
CWE ID 22

Summary

CVE-2024-8898 is a newly disclosed path traversal vulnerability affecting the `install` and `uninstall` API endpoints in version V12 of the parisneo/lollms-webui project, named Strawberry. This vulnerability enables attackers to manipulate user-supplied input with insufficient sanitization, allowing them to create or delete directories with arbitrary paths outside the intended directory structure. Successful exploitation could lead to unauthorized system access, data theft, or denial of service attacks. Users of this software are strongly advised to apply the forthcoming patch or upgrade as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share