CVSS
7.5
CVSS
EPSS
0.5%
Exploit Prediction Score
Published
August 9, 2026
Exploitability
EPSS probability 0.5%
A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment checks. URL-encoded dot-dot sequences (`%2e%2e`) bypass Starlette's built-in path normalization and are resolved by Python's `pathlib`, allowing an unauthenticated attacker to read arbitrary files on the server. This issue has been resolved in version 3.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).