HIGH7.3
PYSEC-2026-1587
LoLLMS vulnerable to Expected Behavior Violation
Quick fix
PYSEC-2026-1587 — lollms: upgrade to the fixed version with the command below.
pip install --upgrade 'lollms>=9.5.1'Details
A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does not adequately secure the `discussion_db_name` parameter, allowing attackers to manipulate the path and potentially write to important system folders.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-6281[ADVISORY]
- https://github.com/parisneo/lollms/commit/26a3ff35acf152b49e1087d5698ad4864c7b6092[WEB]
- https://github.com/parisneo/lollms[PACKAGE]
- https://huntr.com/bounties/0a62f2fb-4e62-4128-9dc4-e8f1d959ac61[WEB]
- https://pypi.org/project/lollms[PACKAGE]
- https://github.com/advisories/GHSA-8mrm-r7h3-c3hj[ADVISORY]