lollms vulnerabilities
CVEs whose affected-version data names the lollms package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
17 CVEsRSS
CVE-2026-1116Medium· 6.1A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms pr…
A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the…
CVE-2026-1163Medium· 4.1parisneo/lollms has an insufficient session expiration vulnerability
parisneo/lollms has an insufficient session expiration vulnerability
CVE-2026-1114Critical· 9.8LoLLMs is vulnerable to Improper Access Control through weak secret key
LoLLMs is vulnerable to Improper Access Control through weak secret key
CVE-2026-0560High· 7.5PoCA Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/exp…
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails …
CVE-2026-0558Critical· 9.8PoCA vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through t…
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other f…
CVE-2026-1117High· 8.2Lollms has an Improper Access Control vulnerability
Lollms has an Improper Access Control vulnerability
CVE-2025-6386High· 7.5Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
CVE-2024-6982High· 8.4LoLLMS Code Injection vulnerability
LoLLMS Code Injection vulnerability
CVE-2024-6971Low· 3.4Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py
Lord of Large Language Models (LoLLMs) Server path traversal vulnerability in lollms_file_system.py
CVE-2024-6281High· 7.3LoLLMS vulnerable to Expected Behavior Violation
LoLLMS vulnerable to Expected Behavior Violation
CVE-2024-6139High· 7.3lollms vulnerable to dot-dot-slash path traversal in XTTS server
lollms vulnerable to dot-dot-slash path traversal in XTTS server
CVE-2024-5824High· 7.4lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE
lollms path traversal vulnerability allows overriding of config.yaml file, leading to RCE
CVE-2024-6085High· 8.6lollms vulnerable to path traversal due to unauthenticated root folder settings change
lollms vulnerable to path traversal due to unauthenticated root folder settings change
CVE-2024-3121Medium· 6.8PoCRemote Code Execution in create_conda_env function in lollms
Remote Code Execution in create_conda_env function in lollms
CVE-2024-3429Critical· 9.8LoLLMS Path Traversal vulnerability
LoLLMS Path Traversal vulnerability
CVE-2024-4330Medium· 4.0path traversal vulnerability was identified in the parisneo/lollms-webui
path traversal vulnerability was identified in the parisneo/lollms-webui
CVE-2024-4078Critical· 9.8LoLLMS Command Injection vulnerability
LoLLMS Command Injection vulnerability