CVE-2024-2361 | parisneo lollms-webui binding.py install_model path traversal
A vulnerability, which was classified as very critical, was found in parisneo lollms-webui. This affects the function install_model of the file lollms_core/lollms/binding.py. The manipulation leads to path traversal: '\..\filename'.
This vulnerability is uniquely identified as CVE-2024-2361. It is possible to initiate the attack remotely. There is no exploit available.