CVE-2026-0560Disclosure(lollms / lollms)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails to validate user-controlled URLs, allowing attackers to make arbitrary HTTP requests to internal services and cloud metadata endpoints. This vulnerability can lead to internal network access, cloud metadata access, information disclosure, port scanning, and potentially remote code execution.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lollms

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-22)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
lollms

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-29: 1Mentions · 2026-03-30: 1Mentions · 2026-04-22: 2PoC Mentioned / Linked · 2026-04-22: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-22: 203-2903-3004-22
Signal classification1 categories
Disclosure
4100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-291
Disclosure1
2026-03-301
Disclosure1
2026-04-222
Disclosure2
Full discourse4 posts
  • Yunus Aydın@aydinnyunuss
    Disclosure

    I found three security issues in parisneo/lollms (versions before 2.2.0). They’re now public as: - https://www.cve.org/CVERecord?id=CVE-2026-0558 - https://www.cve.org/CVERecord?id=CVE-2026-0560 - https://www.cve.org/CVERecord?id=CVE-2026-0562 #security #websecurity #appsec #cve #bugbounty

    Post summary

    The user announces the discovery of three CVEs in the parisneo/lollms project, directing readers to the official CVE listings.

    01080393
    965 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-0560 - high 🚨 LolLMS < 2.2.0 - Server-Side Request Forgery > A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-0560 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE‑2026‑0560, a high‑severity SSRF flaw affecting LolLMS versions prior to 2.2.0, has been publicly disclosed with a reference link that likely hosts detection or PoC information.

    00021164
    942 followersView on X
  • N45HT@N45HTOfficial
    Disclosure

    CVE-2026-0560 💥 LolLMS < 2.2.0 - Server-Side Request Forgery 🤯🔥​ 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-0560 🔗 https://www.cvedetails.com/cve/CVE-2026-0560/ 🔗 https://cloud.projectdiscovery.io/library/CVE-2026-0560 https://t.co/2uV8O08Wcx

    Post summary

    The tweet announces CVE‑2026‑0560, a Server‑Side Request Forgery vulnerability affecting LolLMS versions below 2.2.0, providing links to official NVD and CVE listings but no exploitation details.

    0000035
    70 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0560 A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_do… https://www.cve.org/CVERecord?id=CVE-2026-0560

    Post summary

    The text announces a Server‑Side Request Forgery (SSRF) vulnerability in parisneo/lollms versions before 2.2.0, affecting the `/api/files/export-content` endpoint.

    0000086
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applollmslollms---

Explore more