CVE-2024-3429 is a critical path traversal vulnerability affecting the parisneo/lollms application, specifically in versions prior to 9.6. This flaw, residing in the sanitize_path_from_endpoint and sanitize_path functions, allows attackers to bypass security measures on Windows systems. With a CVSS score of 9.8 (Critical), it enables unauthenticated remote attackers to achieve arbitrary file reading, leading to unauthorized access to sensitive information, potential data compromise, and even denial of service. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered significant community discussion and media coverage, indicating a high level of concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.6CPE matchmatch criteria | cpe:2.3:a:lollms:lollms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.