Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/parisneo/lollms

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A path traversal vulnerability (CVE-2026-10595) exists in parisneo/lollms version 2.1.0 in the SPA catch-all route within backend/routers/ui.py. The vulnerability allows an unauthenticated attacker to read arbitrary files on the server by exploiting improper sanitization of user-controlled path input, specifically bypassing Starlette's path normalization with URL-encoded dot-dot sequences. This issue is resolved in version 3.

Join the discussion

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment checks. URL-encoded dot-dot sequences (`%2e%2e`) bypass Starlette's built-in path normalization and are resolved by Python's `pathlib`, allowing an unauthenticated attacker to read arbitrary files on the server. This issue has been resolved in version 3.

Join the discussion

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the `content` field when deserializing user-provided data. This allows an attacker to inject malicious HTML or JavaScript payloads, which can be executed in the context of another user's browser. Exploitation of this vulnerability can lead to account takeover, session hijacking, or wormable attacks.

Join the discussion

CVE-2026-1115 is a critical stored Cross-Site Scripting (XSS) vulnerability in the social feature of the parisneo/lollms application prior to version 2.2.0. The flaw exists in the create_post function where user input is stored without proper sanitization, allowing malicious JavaScript to be injected and executed in the browsers of users viewing the Home Feed, including administrators. This can lead to severe impacts such as account takeover, session hijacking, and wormable attacks. The vulnerability is resolved in version 2.2.0.

Join the discussion

CVE-2026-1114 is a critical vulnerability in parisneo/lollms version 2.1.0 caused by improper access control due to a weak secret key used for signing JSON Web Tokens (JWT). This weakness allows an attacker to perform an offline brute-force attack to recover the secret key. With the recovered key, attackers can forge administrative tokens, enabling unauthorized privilege escalation and access to restricted endpoints. The vulnerability is fixed in version 2.2.0.

Join the discussion

CVE-2026-0558 is a high-severity vulnerability in parisneo/lollms up to version 2.2.0 where the /api/files/extract-text endpoint does not require authentication. This improper authentication allows unauthenticated users to upload and process files, potentially causing denial of service through resource exhaustion, information disclosure, and violation of security policies. There is no confirmed patch available at this time.

Join the discussion

CVE-2026-0560 is a Server-Side Request Forgery (SSRF) vulnerability in parisneo/lollms versions prior to 2.2.0. It exists in the /api/files/export-content endpoint where the _download_image_to_temp() function does not properly validate user-supplied URLs. This allows attackers to make arbitrary HTTP requests to internal network services and cloud metadata endpoints, potentially leading to information disclosure and internal network reconnaissance. The vulnerability has a high severity with a CVSS score of 7.5. There is no confirmed patch or official fix available at this time.

Join the discussion

A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function in `backend/routers/friends.py` does not implement proper authorization checks, enabling Insecure Direct Object Reference (IDOR) attacks. Specifically, the `/api/friends/requests/{friendship_id}` endpoint fails to verify whether the authenticated user is part of the friendship or the intended recipient of the request. This vulnerability can lead to unauthorized access, privacy violations, and potential social engineering attacks. The issue has been addressed in version 2.2.0.

Join the discussion

A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does not adequately secure the `discussion_db_name` parameter, allowing attackers to manipulate the path and potentially write to important system folders.

Join the discussion

parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoint` function fails to properly sanitize Windows-style paths (backward slash `\`), allowing attackers to perform directory traversal attacks on Windows systems. This vulnerability can be exploited through various routes, including `personalities` and `/del_preset`, to read or delete any file on the Windows filesystem, compromising the system's availability.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:github/parisneo/lollms
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses