CVE-2026-33340
CRITICAL NUCLEILoLLMs WEBUI has unauthenticated Server-Side Request Forgery (SSRF) in /api/proxy endpoint
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-33340. PoCs published by regaan. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-33340, an SSRF vulnerability in lollms-webui. It includes root cause analysis, vulnerable code snippets, proof-of-concept steps, and remediation guidance.
Description
LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all known existing versions of `lollms-webui`. The `@router.post("/api/proxy")` endpoint allows unauthenticated attackers to force the server into making arbitrary GET requests. This can be exploited to access internal services, scan local networks, or exfiltrate sensitive cloud metadata (e.g., AWS/GCP IAM tokens). As of time of publication, no known patched versions are available.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2026-33340, an SSRF vulnerability in lollms-webui. It includes root cause analysis, vulnerable code snippets, proof-of-concept steps, and remediation guidance.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N