-
CVSS Score
-The vulnerability description explicitly identifies the tts_to_file endpoint as the source of improper path validation. Path traversal vulnerabilities typically occur when user input is used directly in file operations without sanitization. While exact code isn't shown, the endpoint name and described vulnerability pattern strongly indicate the handler function for tts_to_file is the vulnerable component. The XTTS server context suggests the file location in the service layer.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| lollms | pip | <= 9.5.1 |
A Semantic Attack on Google Gemini - Read the Latest Research