/Vulnerability Library

LoLLMs WEBUI - Server-Side Request Forgery

CVE-2026-33340
Verified

Description

LoLLMs WEBUI contains a server-side request forgery caused by unauthenticated access to the /api/proxy endpoint, letting attackers force the server to make arbitrary GET requests, exploit requires no authentication.

Severity

Critical

CVSS Score

9.1

Exploit Probability

2%

Published Date

April 9, 2026

Template Author

theamanrawat

CVE-2026-33340.yaml
9.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-33340
CWE ID:
cwe-306

References

https://github.com/ParisNeo/lollms-webui/security/advisories/GHSA-mcwr-5469-pxj4https://nvd.nist.gov/vuln/detail/CVE-2026-33340

Remediation Steps

Update to a patched version once available or apply mitigations to restrict server-side requests.