/Vulnerability Library

LolLMS < 2.2.0 - Server-Side Request Forgery

CVE-2026-0560
Verified

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0. The /api/files/export-content endpoint processes Markdown image URLs by downloading them via _download_image_to_temp() in backend/routers/files.py without any validation, allowing an unauthenticated attacker to supply arbitrary URLs (e.g. cloud metadata endpoints or internal services) that the server will fetch, enabling internal network access, cloud metadata access, information disclosure, port scanning, and potentially remote code execution.

Severity

High

CVSS Score

7.5

Exploit Probability

2%

Affected Product

lollms

Published Date

April 21, 2026

Template Author

ritikchaddha

CVE-2026-0560.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-0560
CWE ID:
cwe-918

References

https://huntr.com/bounties/65e43a5e-b902-4369-b738-1825285a3ea5https://nvd.nist.gov/vuln/detail/CVE-2026-0560https://github.com/parisneo/lollms/commit/76a54f0df2df8a5b254aa627d487b5dc939a0263

Remediation Steps

Update to version 2.2.0 or later.