Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Local File Inclusion in parisneo/lollms-webui
Vulnerability Description
A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation in the `serve_js` function in `app.py`, which allows attackers to perform path traversal attacks. This can lead to unauthorized access to arbitrary files on the server, potentially exposing sensitive information such as private SSH keys, configuration files, and source code.
CVSS Information
N/A
Vulnerability Type
路径遍历:’..filename’
Vulnerability Title
LoLLMs 安全漏洞
Vulnerability Description
LoLLMs是Saifeddine ALOUI个人开发者的一个大型语言多模式系统的 Web UI。 LoLLMs v9.8之前版本存在安全漏洞,该漏洞源于app.py中的serve_js函数未验证路径连接。攻击者利用该漏洞可以访问服务器上的任意文件,并可能暴露敏感信息,例如私钥、配置文件和源代码。
CVSS Information
N/A
Vulnerability Type
N/A