{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T20:24:35.851","vulnerabilities":[{"cve":{"id":"CVE-2024-6281","sourceIdentifier":"security@huntr.dev","published":"2024-07-20T04:15:05.260","lastModified":"2026-06-17T08:17:41.983","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does not adequately secure the `discussion_db_name` parameter, allowing attackers to manipulate the path and potentially write to important system folders."},{"lang":"es","value":"Existe una vulnerabilidad de path traversal en la función `apply_settings` de las versiones parisneo/lollms anteriores a la 9.5.1. La función `sanitize_path` no protege adecuadamente el parámetro `discussion_db_name`, lo que permite a los atacantes manipular la ruta y potencialmente escribir en carpetas importantes del sistema."}],"affected":[{"source":"security@huntr.dev","affectedData":[{"vendor":"parisneo","product":"parisneo/lollms","versions":[{"version":"unspecified","lessThan":"9.5.1","versionType":"custom","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"parisneo","product":"lollms","defaultStatus":"unknown","cpes":["cpe:2.3:a:parisneo:lollms:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"9.5.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-23T15:08:15.333045Z","id":"CVE-2024-6281","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/parisneo/lollms/commit/26a3ff35acf152b49e1087d5698ad4864c7b6092","source":"security@huntr.dev"},{"url":"https://huntr.com/bounties/0a62f2fb-4e62-4128-9dc4-e8f1d959ac61","source":"security@huntr.dev"},{"url":"https://github.com/parisneo/lollms/commit/26a3ff35acf152b49e1087d5698ad4864c7b6092","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://huntr.com/bounties/0a62f2fb-4e62-4128-9dc4-e8f1d959ac61","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}