11.0.0
1 years ago
2 months ago
Known vulnerabilities in the lollms package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
lollms is a python library for AI personality definition Affected versions of this package are vulnerable to Missing Critical Step in Authentication due to a missing How to fix Missing Critical Step in Authentication? A fix was pushed into the | [0,) |
lollms is a python library for AI personality definition Affected versions of this package are vulnerable to Arbitrary Command Injection in the How to fix Arbitrary Command Injection? Upgrade | [,11.0.0) |
lollms is a python library for AI personality definition Affected versions of this package are vulnerable to Directory Traversal over the How to fix Directory Traversal? A fix was pushed into the | [0,) |
lollms is a python library for AI personality definition Affected versions of this package are vulnerable to Relative Path Traversal in the This vulnerability is a bypass to the fix introduced for the vulnerability described in CVE-2024-6985. How to fix Relative Path Traversal? A fix was pushed into the | [0,) |
lollms is a python library for AI personality definition Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? A fix was pushed into the | [0,) |
lollms is a python library for AI personality definition Affected versions of this package are vulnerable to Directory Traversal through the How to fix Directory Traversal? Upgrade | [,9.5.1) |
lollms is a python library for AI personality definition Affected versions of this package are vulnerable to Relative Path Traversal due to improper sanitization of the How to fix Relative Path Traversal? Upgrade | [,9.5.1) |
lollms is a python library for AI personality definition Affected versions of this package are vulnerable to Directory Traversal through the How to fix Directory Traversal? Upgrade | [,9.5.1) |
lollms is a python library for AI personality definition Affected versions of this package are vulnerable to Improper Control of Generation of Code ('Code Injection') through the How to fix Improper Control of Generation of Code ('Code Injection')? There is no fixed version for | [0,) |
lollms is a python library for AI personality definition Affected versions of this package are vulnerable to Path Traversal in speaker wav and output file paths. This vulnerability can be abused to write audio files compatible with XTTS to arbitrary locations on the system, and also enumerate such file paths on the system. How to fix Path Traversal? There is no fixed version for | [0,) |
lollms is a python library for AI personality definition Affected versions of this package are vulnerable to Path Traversal due to the possibility of performing an unauthenticated root folder settings change. An attacker can read arbitrary files on the system. Note: This vulnerability can be abused to write audio files compatible with XTTS to arbitrary locations on the system, and also enumerate such file paths on the system. How to fix Path Traversal? There is no fixed version for | [0,) |
lollms is a python library for AI personality definition Affected versions of this package are vulnerable to Command Injection in the How to fix Command Injection? Upgrade | [0,9.5.1) |