CVE-2026-0558

CRITICAL

Unauthenticated File Upload in parisneo/lollms

Title source: cna

Description

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other file-related endpoints, and lacks the `Depends(get_current_active_user)` dependency. This issue can lead to denial of service (DoS) through resource exhaustion, information disclosure, and violation of the application's documented security policies.

Scores

CVSS v3 9.8
EPSS 0.0031
EPSS Percentile 53.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (2)
lollms/lollms < 2.1.0
parisneo/parisneo/lollms unspecified - 2.2.0
Published Mar 29, 2026
Tracked Since Mar 29, 2026