← Vulnerability feed

Vulnerability record · CVE-2024-1873 · published 6 June 2024

CVE-2024-1873: Lollms web ui path traversal vulnerability

Lollms · Lollms Web Ui

parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0. The endpoint improperly handles file paths, allowing attackers to specify absolute paths when interacting with the `DiscussionsDB` instance. This flaw enables attackers to create directories anywhere on the system where the application has permissions, potentially leading to denial of service by creating directories with names of critical files, such as HTTPS certificate files, causing server startup failures. Additionally, attackers can manipulate the database path, resulting in the loss of client data by constantly changing the file location to an attacker-controlled location, scattering the data across the filesystem and making recovery difficult.

9.1 CVSS 3.1 Critical EPSS 13% · top 3.7% CWE-22 · Path traversal
9.1CVSS 3.1 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0. The endpoint improperly handles file paths, allowing attackers to specify absolute paths when interacting with the `DiscussionsDB` instance. This flaw enables attackers to create directories anywhere on the system where the application has permissions, potentially leading to denial of service by creating directories with names of critical files, such as HTTPS certificate files, causing server startup failures. Additionally, attackers can manipulate the database path, resulting in the loss of client data by constantly changing the file location to an attacker-controlled location, scattering the data across the filesystem and making recovery difficult.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-1873 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-8898Lollms web ui path traversal vulnerabilityA path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerab…EPSS 0.80%9.8CVE-2024-4320Lollms web ui path traversal vulnerabilityA remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within…EPSS 34%9.8CVE-2024-3322Lollms web ui path traversal vulnerabilityA path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5…EPSS 0.73%9.8CVE-2024-2624Lollms web ui path traversal vulnerabilityA path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the `@router.get("/swit…EPSS 1.4%9.8CVE-2024-2359Lollms web ui os command injection vulnerabilityA vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbitrary code. The issu…EPSS 1.2%9.8CVE-2024-2360Lollms web ui path traversal vulnerabilityparisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplie…EPSS 1.9%9.8CVE-2024-5482Lollms web ui server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui application, affecting the lates…EPSS 0.65%9.8CVE-2024-4326Lollms web ui vulnerabilityA vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insuffici…EPSS 0.97%

Source: NIST National Vulnerability Database (record CVE-2024-1873), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.