CVE-2026-33340Disclosure(lollms / lollms_web_ui)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all known existing versions of `lollms-webui`. The `@router.post("/api/proxy")` endpoint allows unauthenticated attackers to force the server into making arbitrary GET requests. This can be exploited to access internal services, scan local networks, or exfiltrate sensitive cloud metadata (e.g., AWS/GCP IAM tokens). As of time of publication, no known patched versions are available.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lollms_web_ui

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-24); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
lollms_web_ui

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-24: 4Mentions · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-14: 1Technical Details · 2026-03-24: 4Technical Details · 2026-04-14: 103-2404-14
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-244
Disclosure4
2026-04-141
Disclosure1
Full discourse5 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-33340 - critical 🚨 LoLLMs WEBUI - Server-Side Request Forgery > LoLLMs WEBUI contains a server-side request forgery caused by unauthenticated access ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-33340 @pdnuclei #NucleiTemplates #cve

    Post summary

    A critical SSRF flaw (CVE-2026-33340) in LoLLMs WEBUI is disclosed with a linked resource, but no exploit code, active exploitation, or patch information is provided.

    00011180
    959 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33340 - Critical LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all kno... https://www.thehackerwire.com/vulnerability/CVE-2026-33340/ https://t.co/ThCqYKKR96

    Post summary

    A critical SSRF vulnerability (CVE‑2026‑33340) was disclosed for LoLLMs WEBUI, with technical details highlighted but no active exploitation, PoC, or patch information provided.

    0000039
    145 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33340 LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been … https://www.cve.org/CVERecord?id=CVE-2026-33340

    Post summary

    A critical SSRF vulnerability disclosed in LoLLMs WEBUI; no PoC, exploit, or active exploitation mentioned.

    0000067
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-33340: CRITICAL] Critical Server-Side Request Forgery (SSRF) vulnerability found in LoLLMs WEBUI. Unauthenticated attackers can exploit to access sensitive data & internal services, no fix availabl...#cve,CVE-2026-33340,#cybersecurity https://cvefind.com/CVE-2026-33340

    Post summary

    A critical SSRF vulnerability in LoLLMs Web UI that permits unauthenticated attackers to reach internal services has been disclosed, with no patch or workaround currently available.

    0000046
    606 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33340: LoLLMs WEBUI has unauthenticated... Unauthenticated SSRF in LoLLMs `/api/proxy` endpoint = instant cloud metadata theft and internal network pivot - zero p... https://zerodaysignal.com/vulnerability/CVE-2026-33340 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces an unauthenticated SSRF vulnerability in LoLLMs' `/api/proxy` endpoint that enables cloud metadata theft and network pivot, providing technical details but no PoC, exploit, patch, or active exploitation evidence.

    0000056
    164 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applollmslollms_web_ui---

Explore more