CVE-2026-0562Disclosure(lollms / lollms)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function in `backend/routers/friends.py` does not implement proper authorization checks, enabling Insecure Direct Object Reference (IDOR) attacks. Specifically, the `/api/friends/requests/{friendship_id}` endpoint fails to verify whether the authenticated user is part of the friendship or the intended recipient of the request. This vulnerability can lead to unauthorized access, privacy violations, and potential social engineering attacks. The issue has been addressed in version 2.2.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lollms

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-29); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
lollms

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-29: 2Mentions · 2026-03-30: 1Mentions · 2026-04-18: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-18: 103-2903-3004-18
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-292
Disclosure1General1
2026-03-301
Disclosure1
2026-04-181
Disclosure1
Full discourse4 posts
  • Yunus Aydın@aydinnyunuss
    Disclosure

    I found an IDOR in LollMS friend request handling: any authenticated user could accept or reject someone else's pending request by guessing sequential friendship IDs (CVE-2026-0562). Full write-up: https://aydinnyunus.github.io/2026/04/18/idor-lollms-friend-request-cve-2026-0562/ #security #websecurity #appsec #cve #bugbounty

    Post summary

    An IDOR vulnerability (CVE‑2026‑0562) lets authenticated users accept or reject others’ friend requests by guessing sequential ID numbers; no exploit, patch, or active attacks are mentioned.

    11020121.1K
    1.1K followersView on X
  • Yunus Aydın@aydinnyunuss
    Disclosure

    I found three security issues in parisneo/lollms (versions before 2.2.0). They’re now public as: - https://www.cve.org/CVERecord?id=CVE-2026-0558 - https://www.cve.org/CVERecord?id=CVE-2026-0560 - https://www.cve.org/CVERecord?id=CVE-2026-0562 #security #websecurity #appsec #cve #bugbounty

    Post summary

    Three CVE vulnerabilities discovered in parisneo/lollms before version 2.2.0 have been publicly disclosed via CVE database links.

    01080393
    965 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0562 A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. Th… https://www.cve.org/CVERecord?id=CVE-2026-0562

    Post summary

    The tweet announces CVE-2026-0562, detailing a cross‑user friend‑request privilege issue and linking to the official CVE record, with no evidence of PoC, exploit code, active exploitation, or remediation disclosed.

    0000082
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-0562 - High A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` fu... https://www.thehackerwire.com/vulnerability/CVE-2026-0562/ https://t.co/wTg4W3YB5N

    Post summary

    CVE-2026-0562 is a high‑severity flaw in parisneo/lollms that allows authenticated users to accept or reject friend requests on behalf of others, but no PoC, exploit tool, active exploitation, patch, or false positive information is provided.

    0000040
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applollmslollms---

Explore more