漏洞详情: CVE-2024-5443

漏洞标题
Remote Code Execution via Path Traversal in parisneo/lollms
来源:NVD
LoLLMs 安全漏洞
来源:CNNVD
漏洞描述
CVE-2024-4320 describes a vulnerability in the parisneo/lollms software, specifically within the `ExtensionBuilder().build_extension()` function. The vulnerability arises from the `/mount_extension` endpoint, where a path traversal issue allows attackers to navigate beyond the intended directory structure. This is facilitated by the `data.category` and `data.folder` parameters accepting empty strings (`""`), which, due to inadequate input sanitization, can lead to the construction of a `package_path` that points to the root directory. Consequently, if an attacker can create a `config.yaml` file in a controllable path, this path can be appended to the `extensions` list and trigger the execution of `__init__.py` in the current directory, leading to remote code execution. The vulnerability affects versions up to 5.9.0, and has been addressed in version 9.8.
来源:NVD
LoLLMs是Saifeddine ALOUI个人开发者的一个大型语言多模式系统的 Web UI。 LoLLMs 5.9.0及之前版本存在安全漏洞,该漏洞源于存在路径遍历问题,允许攻击者远程执行代码。
来源:CNNVD
NVD 暂无描述信息
来源:神龙机器人
漏洞评分(CVSS)
NVD 暂无评分
来源:NVD
漏洞类别
路径遍历:’..filename’
来源:NVD
其他
来源:CNNVD
相关链接