CVE-2026-0560

HIGH NUCLEI

Server-Side Request Forgery (SSRF) in parisneo/lollms

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-0560. PoCs published by Max78000. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository describes a Server-Side Request Forgery (SSRF) vulnerability in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. It identifies the vulnerable function (`_download_image_to_temp()`) but contains no exploit code or technical proof-of-concept.

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails to validate user-controlled URLs, allowing attackers to make arbitrary HTTP requests to internal services and cloud metadata endpoints. This vulnerability can lead to internal network access, cloud metadata access, information disclosure, port scanning, and potentially remote code execution.

Exploits (1)

github STUB
by Max78000 · poc
https://github.com/Max78000/CVE-2026-0560-lollms

The repository describes a Server-Side Request Forgery (SSRF) vulnerability in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. It identifies the vulnerable function (`_download_image_to_temp()`) but contains no exploit code or technical proof-of-concept.

Classification
Stub 95%
Attack Type
Ssrf
Complexity
Moderate
Reliability
Theoretical
Target: parisneo/lollms < 2.2.0
No auth needed
Prerequisites: Access to the vulnerable `/api/files/export-content` endpoint · User-controlled input to specify arbitrary URLs
mistral-large-3 · analyzed Jul 23, 2026 Full analysis →

Nuclei Templates (1)

LolLMS < 2.2.0 - Server-Side Request Forgery
HIGHby ritikchaddha
Shodan: http.title:"lollms"

Scores

CVSS v3 7.5
EPSS 0.0176
EPSS Percentile 75.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
lollms/lollms < 2.1.0
parisneo/parisneo/lollms unspecified - 2.2.0
Published Mar 29, 2026
Tracked Since Mar 29, 2026