VulnSea

lollms vulnerabilities

CVEs whose affected-version data names the lollms package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

17 CVEsRSS

CVE-2026-1116Medium· 6.1
5mo ago

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms pr…

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the…

Sunlitlollms · lollmsEPSS 0.26%via OSV
CVE-2026-1163Medium· 4.1
5mo ago

parisneo/lollms has an insufficient session expiration vulnerability

parisneo/lollms has an insufficient session expiration vulnerability

Sunlitlollms · lollmsEPSS 0.21%via OSV
CVE-2026-1114Critical· 9.8
5mo ago

LoLLMs is vulnerable to Improper Access Control through weak secret key

LoLLMs is vulnerable to Improper Access Control through weak secret key

Midnightlollms · lollmsEPSS 0.54%via OSV
CVE-2026-0560High· 7.5PoC
5mo ago

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/exp…

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails …

Midnightlollms · lollmsEPSS 1.8%via OSV
CVE-2026-0558Critical· 9.8PoC
5mo ago

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through t…

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other f…

Abyssallollms · lollmsEPSS 1.9%via OSV
CVE-2026-1117High· 8.2
7mo ago

Lollms has an Improper Access Control vulnerability

Lollms has an Improper Access Control vulnerability

Twilightlollms · lollmsEPSS 0.56%via OSV
CVE-2025-6386High· 7.5
1y ago

Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function

Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function

Twilightlollms · lollmsEPSS 0.37%via OSV
CVE-2024-6982High· 8.4
1y ago

LoLLMS Code Injection vulnerability

LoLLMS Code Injection vulnerability

Twilightlollms · lollmsEPSS 0.46%via OSV
CVE-2024-6971Low· 3.4
1y ago

Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py

Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py

Sunlitlollms · lollmsEPSS 0.32%via OSV
CVE-2024-6281High· 7.3
2y ago

LoLLMS vulnerable to Expected Behavior Violation

LoLLMS vulnerable to Expected Behavior Violation

Twilightlollms · lollmsEPSS 0.27%via OSV
CVE-2024-6139High· 7.3
2y ago

lollms vulnerable to dot-dot-slash path traversal in XTTS server

lollms vulnerable to dot-dot-slash path traversal in XTTS server

Twilightlollms · lollmsEPSS 0.52%via OSV
CVE-2024-5824High· 7.4
2y ago

lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE

lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE

Twilightlollms · lollmsEPSS 0.45%via OSV
CVE-2024-6085High· 8.6
2y ago

lollms vulnerable to path traversal due to unauthenticated root folder settings change

lollms vulnerable to path traversal due to unauthenticated root folder settings change

Twilightlollms · lollmsEPSS 0.64%via OSV
CVE-2024-3121Medium· 6.8PoC
2y ago

Remote Code Execution in create_conda_env function in lollms

Remote Code Execution in create_conda_env function in lollms

Twilightlollms · lollmsEPSS 0.45%via OSV
CVE-2024-3429Critical· 9.8
2y ago

LoLLMS Path Traversal vulnerability

LoLLMS Path Traversal vulnerability

Midnightlollms · lollmsEPSS 28%via OSV
CVE-2024-4330Medium· 4.0
2y ago

path traversal vulnerability was identified in the parisneo/lollms-webui

path traversal vulnerability was identified in the parisneo/lollms-webui

Sunlitlollms · lollmsEPSS 0.29%via OSV
CVE-2024-4078Critical· 9.8
2y ago

LoLLMS Command Injection vulnerability

LoLLMS Command Injection vulnerability

Midnightlollms · lollmsEPSS 0.92%via OSV
lollms vulnerabilities (CVEs) · VulnSea