A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other file-related endpoints, and lacks the `Depends(get_current_active_user)` dependency. This issue can lead to denial of service (DoS) through resource exhaustion, information disclosure, and violation of the application's documented security policies.
References
| Link | Resource |
|---|---|
| https://github.com/parisneo/lollms/commit/a6625dc83786ff21d109b0d545ca61b770607ef3 | Patch |
| https://huntr.com/bounties/0a722001-89ce-4c91-b6a6-a55ee5ba2113 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
31 Mar 2026, 19:45
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Lollms
Lollms lollms |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CPE | cpe:2.3:a:lollms:lollms:*:*:*:*:*:*:*:* | |
| References | () https://github.com/parisneo/lollms/commit/a6625dc83786ff21d109b0d545ca61b770607ef3 - Patch | |
| References | () https://huntr.com/bounties/0a722001-89ce-4c91-b6a6-a55ee5ba2113 - Exploit, Issue Tracking, Third Party Advisory | |
| CWE | NVD-CWE-noinfo |
29 Mar 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-29 18:16
Updated : 2026-03-31 19:45
NVD link : CVE-2026-0558
Mitre link : CVE-2026-0558
CVE.ORG link : CVE-2026-0558
JSON object : View
Products Affected
lollms
- lollms
CWE
