CVE-2026-0558
CRITICALUnauthenticated File Upload in parisneo/lollms
Title source: cnaDescription
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other file-related endpoints, and lacks the `Depends(get_current_active_user)` dependency. This issue can lead to denial of service (DoS) through resource exhaustion, information disclosure, and violation of the application's documented security policies.
Scores
CVSS v3
9.8
EPSS
0.0031
EPSS Percentile
53.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-287
Status
published
Products (2)
lollms/lollms
< 2.1.0
parisneo/parisneo/lollms
unspecified - 2.2.0
Published
Mar 29, 2026
Tracked Since
Mar 29, 2026