A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of user-provided file paths in the `tts_to_file` endpoint.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2190 A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of user-provided file paths in the `tts_to_file` endpoint.
Github GHSA Github GHSA GHSA-w9qf-83jg-2x6c lollms vulnerable to dot-dot-slash path traversal in XTTS server
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2024-08-01T21:33:04.959Z

Reserved: 2024-06-18T18:53:55.136Z

Link: CVE-2024-6139

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:04.959Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-27T19:15:20.023

Modified: 2024-11-21T09:49:02.910

Link: CVE-2024-6139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:23:55Z