CVE-2026-0560
HIGH NUCLEIServer-Side Request Forgery (SSRF) in parisneo/lollms
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-0560. PoCs published by Max78000. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository describes a Server-Side Request Forgery (SSRF) vulnerability in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. It identifies the vulnerable function (`_download_image_to_temp()`) but contains no exploit code or technical proof-of-concept.
Description
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails to validate user-controlled URLs, allowing attackers to make arbitrary HTTP requests to internal services and cloud metadata endpoints. This vulnerability can lead to internal network access, cloud metadata access, information disclosure, port scanning, and potentially remote code execution.
Exploits (1)
The repository describes a Server-Side Request Forgery (SSRF) vulnerability in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. It identifies the vulnerable function (`_download_image_to_temp()`) but contains no exploit code or technical proof-of-concept.
Nuclei Templates (1)
http.title:"lollms"
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N