CVE-2026-1163Medium· 4.1▾ Sunlitparisneo/lollms has an insufficient session expiration vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an attacker to continue using an old session token. This issue arises due to the absence of logic to reject requests after a period of inactivity and the excessively long default session duration of 31 days. The vulnerability enables an attacker to maintain persistent access to a compromised account, even after the victim resets their password.
lollms <= 11.0.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-6139High· 7.3lollms vulnerable to dot-dot-slash path traversal in XTTS server
CVE-2024-6982High· 8.4LoLLMS Code Injection vulnerability
CVE-2025-6386High· 7.5Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
CVE-2024-4330Medium· 4.0path traversal vulnerability was identified in the parisneo/lollms-webui
CVE-2024-6085High· 8.6lollms vulnerable to path traversal due to unauthenticated root folder settings change
CVE-2024-6971Low· 3.4Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py