parisneo/lollms-webui contains a path traversal caused by improper handling of 'category' parameter in /list_personalities endpoint, letting attackers list arbitrary directories, exploit requires control over 'category' parameter.
id: CVE-2024-4322
info:
name: LoLLMS WebUI < 9.8 - Path Traversal
author: MJ-bin
severity: hi
...