lollms
PyPI24 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting lollmspage 1 of 1
- CVE-2024-3121MEDIUMCVSS 3.3EG 6.82024-06-24
vulnerable: 1.1.10 ... 9.5.1 (265 versions)
A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0. The vulnerability arises from the use of shell=True in the subprocess.Popen function, which allows an attacker …
- CVE-2024-3429CRITICALCVSS 9.8EG 9.8fixed in 9.5.02024-06-06
vulnerable: 1.1.10 ... 9.3.0 (263 versions)
A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` functions in `lollms_core\lollms\security.py`. This vulnerability allows for arbitrary file…
- CVE-2024-4078CRITICALCVSS 9.8EG 9.8fixed in 9.5.02024-05-16
vulnerable: 1.1.10 ... 9.3.0 (263 versions)
A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sanitization of user input. The issue arises from the lack of path sanitization when handlin…
- CVE-2024-4315CRITICALCVSS 9.1EG 9.1fixed in 9.5.02024-06-12
vulnerable: 1.1.10 ... 9.3.0 (263 versions)
parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoint` function fails to properly sanitize Windows-style paths (backward slash `\`), allowing…
- CVE-2024-4330MEDIUMCVSS 3.3EG 4.02024-05-30
vulnerable: 9.6
A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulnerability arises due to improper handling of user-supplied input in the 'list_personalities' endpoint. By craft…
- CVE-2024-4881HIGHCVSS 7.5EG 7.5fixed in 9.5.0 or 5.9.0, by version range2024-06-06
vulnerable: 1.1.10 ... 5.8.8 (237 versions)
A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions, but fixed in version 5.9.0. The vulnerability arises due to improper validation of file paths between Windo…
- CVE-2024-5443CRITICALCVSS 9.8EG 9.8fixed in 9.5.12024-06-22
vulnerable: 5.9.0 ... 9.5.0 (27 versions)
CVE-2024-4320 describes a vulnerability in the parisneo/lollms software, specifically within the `ExtensionBuilder().build_extension()` function. The vulnerability arises from the `/mount_extension` endpoint, where a path traversal issue a…
- CVE-2024-5824HIGHCVSS 7.4EG 7.4fixed in 9.5.02024-06-27
vulnerable: 1.1.10 ... 9.3.0 (263 versions)
A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the `configs/config.yaml` file. This can lead to remote code execution by changing server configurati…
- CVE-2024-6085HIGHCVSS 8.6EG 8.62024-06-27
vulnerable: 1.1.10 ... 9.5.1 (265 versions)
A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerability arises from the ability to perform an unauthenticated root folder settings change. Although the read file endpoint is…
- CVE-2024-6139HIGHCVSS 7.3EG 7.32024-06-27
vulnerable: 1.1.10 ... 9.5.1 (265 versions)
A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arise…
- CVE-2024-6281HIGHCVSS 7.3EG 7.3fixed in 9.5.12024-07-20
vulnerable: 1.1.10 ... 9.5.0 (264 versions)
A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does not adequately secure the `discussion_db_name` parameter, allowing attackers to manipulate…
- CVE-2024-6581CRITICALCVSS 9.0EG 9.02024-10-29
vulnerable: 1.1.10 ... 9.5.1 (266 versions)
A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomplete filtering in the sanitize_svg function, this can lead to cross-site scripting (XSS) v…
- CVE-2024-6971MEDIUMCVSS 4.4EG 4.42024-10-11
vulnerable: 1.1.10 ... 9.5.1 (265 versions)
A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and `vectorize_folder` do not implement securit…
- CVE-2024-6982HIGHCVSS 8.4EG 8.4fixed in 11.0.02025-03-20
vulnerable: 1.1.10 ... 9.5.1 (265 versions)
A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability arises from the use of Python's `eval()` function to evaluate mathematical expressions within a Python sandbox that di…
- CVE-2024-6985MEDIUMCVSS 4.4EG 4.4fixed in 5.9.02024-10-11
vulnerable: 1.1.10 ... 5.8.8 (237 versions)
A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnerability allows an attacker to read any folder in the personality_folder on the victim's computer, even though sanitize_p…
- CVE-2025-6386HIGHCVSS 7.5EG 7.52025-07-07
vulnerable: 1.1.10 ... 9.5.1 (266 versions)
The parisneo/lollms repository is affected by a timing attack vulnerability in the `authenticate_user` function within the `lollms_authentication.py` file. This vulnerability allows attackers to enumerate valid usernames and guess password…
- CVE-2026-0558CRITICALCVSS 9.8EG 9.8fixed in 2.1.12026-03-29
vulnerable: 1.1.10 ... 2.1.0 (118 versions)
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other fil…
- CVE-2026-0560HIGHCVSS 7.5EG 7.5fixed in 2.1.12026-03-29
vulnerable: 1.1.10 ... 2.1.0 (118 versions)
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails to…
- CVE-2026-0562HIGHCVSS 8.3EG 8.3fixed in 2.1.12026-03-29
vulnerable: 1.1.10 ... 2.1.0 (118 versions)
A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function in `backend/routers/friends.py` does not…
- CVE-2026-1114CRITICALCVSS 9.8EG 9.8fixed in 2.2.02026-04-07
vulnerable: 1.1.10 ... 2.1.0 (118 versions)
In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT). This vulnerability allows an attacker to perform an offl…
- CVE-2026-1115CRITICALCVSS 9.6EG 9.6fixed in 2.2.02026-04-10
vulnerable: 1.1.10 ... 2.1.9 (173 versions)
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` function within `backend/routers/social/_…
- CVE-2026-1116HIGHCVSS 6.1EG 8.2fixed in 2.1.12026-04-12
vulnerable: 1.1.10 ... 2.1.0 (118 versions)
A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the `…
- CVE-2026-1117HIGHCVSS 8.2EG 8.2fixed in 2.1.02026-02-02
vulnerable: 1.1.10 ... 2.0.9 (117 versions)
A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated access to sensitive Socket.IO events. The `add_events` function registers event handlers such as `generate_text`, `cance…
- CVE-2026-1163MEDIUMCVSS 4.1EG 4.12026-04-08
vulnerable: 1.1.10 ... 9.5.1 (266 versions)
An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an attacker to continue using an old session token. This…
Check whether lollms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for lollms CVEs against the assets you own.
Book a Demo →