CVE-2026-1117Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated access to sensitive Socket.IO events. The `add_events` function registers event handlers such as `generate_text`, `cancel_generation`, `generate_msg`, and `generate_msg_from` without implementing authentication or authorization checks. This allows unauthenticated clients to execute resource-intensive or state-altering operations, leading to potential denial of service, state corruption, and race conditions. Additionally, the use of global flags (`lollmsElfServer.busy`, `lollmsElfServer.cancel_gen`) for state management in a multi-client environment introduces further vulnerabilities, enabling one client's actions to affect the server's state and other clients' operations. The lack of proper access control and reliance on insecure global state management significantly impacts the availability and integrity of the service.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-02: 3Technical Details · 2026-02-02: 302-02
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-1117 A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated access to sensitive http://Socket.IO events. The `add_ev… https://www.cve.org/CVERecord?id=CVE-2026-1117

    Post summary

    CVE‑2026‑1117 is a vulnerability in lollms_generation_events.py that permits unauthenticated access to sensitive Socket.IO events.

    00030302
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1117 Unauthenticated http://Socket.IO Event Manipulation in parisneo/lollms 5.9.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1117

    Post summary

    A new unauthenticated Socket.IO event manipulation vulnerability (CVE-2026-1117) has been disclosed for parisneo/lollms 5.9.0.

    0000077
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1117 - High A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated access to sensitive http://Socket.IO events. The `add_events` function registers... https://www.thehackerwire.com/vulnerability/CVE-2026-1117/ https://t.co/5eqK1pab4z

    Post summary

    The post announces CVE‑2026‑1117, describing an unauthenticated access flaw in the lollms_generation_events.py component of parisneo/lollms 5.9.0, and provides a link to an external article for more details.

    0000068
    113 followersView on X

Explore more