LOW3.4
PYSEC-2026-1585
Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py
Details
A path traversal vulnerability exists in the ParisNeo/lollms repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and `vectorize_folder` do not implement security measures such as `sanitize_path_from_endpoint` or `sanitize_path`. This allows an attacker to perform vectorize operations on `.sqlite` files in any directory on the victim's computer, potentially installing multiple packages and causing a crash.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/lollms
Introduced in:
0No fixed version published yet for lollms (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-6971[ADVISORY]
- https://github.com/ParisNeo/lollms/commit/aeace796d861e922133b769710019608a6363264[WEB]
- https://github.com/ParisNeo/lollms[PACKAGE]
- https://huntr.com/bounties/fbfe7cd0-99fb-4305-bd07-8b573364109e[WEB]
- https://pypi.org/project/lollms[PACKAGE]
- https://github.com/advisories/GHSA-7pgr-32fx-c6x9[ADVISORY]