Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Path Traversal in parisneo/lollms-webui
Vulnerability Description
A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which can be exploited to traverse directories outside the intended path.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
LoLLMs Web UI 安全漏洞
Vulnerability Description
LoLLMs Web UI是Saifeddine ALOUI个人开发者的一个大型语言与多模态系统的 Web 用户界面。 LoLLMs Web UI V12版本存在安全漏洞,该漏洞源于install和uninstall API端点未对用户输入进行充分清理,可能导致路径遍历。
CVSS Information
N/A
Vulnerability Type
N/A