HIGH7.4
PYSEC-2026-1592
lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE
Quick fix
PYSEC-2026-1592 — lollms: upgrade to the fixed version with the command below.
pip install --upgrade 'lollms>=9.5.0'Details
A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the `configs/config.yaml` file. This can lead to remote code execution by changing server configuration properties such as `force_accept_remote_access` and `turn_on_code_validation`.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-5824[ADVISORY]
- https://github.com/parisneo/lollms/commit/eda3af5f5c4ea9b2f3569f72f8d05989e29367fc[WEB]
- https://github.com/parisneo/lollms[PACKAGE]
- https://huntr.com/bounties/9ceb7cf9-a7cd-4699-b3f8-d0999d2b49fd[WEB]
- https://pypi.org/project/lollms[PACKAGE]
- https://github.com/advisories/GHSA-m45c-v46h-c788[ADVISORY]