CVE-2024-8581: Lollms Web UI
Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.
A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the `filename` value, causing a Path Traversal error.
Affected products
- Lollms Lollms Web UI: version 12 only
Published 2025-03-20. Last modified 2026-06-17.