LoLLMs WEBUI - Server-Side Request Forgery
CVE-2026-33340
Verified
Description
LoLLMs WEBUI contains a server-side request forgery caused by unauthenticated access to the /api/proxy endpoint, letting attackers force the server to make arbitrary GET requests, exploit requires no authentication.
Severity
Critical
CVSS Score
9.1
Exploit Probability
2%
Published Date
April 9, 2026
Template Author
theamanrawat
CVE-2026-33340.yaml
9.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-33340
CWE ID:
cwe-306
Remediation Steps
Update to a patched version once available or apply mitigations to restrict server-side requests.