CVE-2024-6139
Last modified
CVE-2024-6139 is a vulnerability of currently unknown severity. A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of user-provided file paths in the `tts_to_file` endpoint.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-6139?
How severe is CVE-2024-6139?
How do I fix CVE-2024-6139?
Are you affected by CVE-2024-6139?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
