CVE-2024-8581: Lollms Web UI

Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.

A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the `filename` value, causing a Path Traversal error.

Affected products

  • Lollms Lollms Web UI: version 12 only

Published 2025-03-20. Last modified 2026-06-17.