CVE-2024-8898: Lollms Web UI

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which can be exploited to traverse directories outside the intended path.

Affected products

  • Lollms Lollms Web UI: version 12 only

Published 2025-03-20. Last modified 2026-06-17.