/Vulnerability Library

LOLLMS WebUI - Absolute Path Traversal

CVE-2024-6250
Verified

Description

An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the open_file endpoint of lollms_advanced.py. The sanitize_path function with allow_absolute_path=True allows an attacker to access arbitrary files and directories on a Windows system. This vulnerability can be exploited to read any file and list arbitrary directories on the affected system.

Severity

High

CVSS Score

7.5

Exploit Probability

2%

Affected Product

lollms_web_ui

Published Date

January 28, 2026

Template Author

ritikchaddha

CVE-2024-6250.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2024-6250
CWE ID:
cwe-36

References

https://huntr.com/bounties/11a8bf9d-16f3-49b3-b5fc-ad36d8993c73https://nvd.nist.gov/vuln/detail/CVE-2024-6250https://github.com/parisneo/lollms-webui

Remediation Steps

Update to the latest version where the vulnerability is fixed or modify the `sanitize_path` function to disallow absolute paths.