Description
A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of user-provided file paths in the `tts_to_file` endpoint.
Published: 2024-06-27
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2190 A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of user-provided file paths in the `tts_to_file` endpoint.
Github GHSA Github GHSA GHSA-w9qf-83jg-2x6c lollms vulnerable to dot-dot-slash path traversal in XTTS server
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2024-08-01T21:33:04.959Z

Reserved: 2024-06-18T18:53:55.136Z

Link: CVE-2024-6139

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:04.959Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-27T19:15:20.023

Modified: 2024-11-21T09:49:02.910

Link: CVE-2024-6139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:23:55Z

Weaknesses