CVE-2024-8898: Lollms Web UI
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which can be exploited to traverse directories outside the intended path.
Affected products
- Lollms Lollms Web UI: version 12 only
Published 2025-03-20. Last modified 2026-06-17.