Report: CVE-2026-0560 - Server-Side Request Forgery (SSRF) in parisneo/lollms - Expert Insights

Report: CVE-2026-0560 - Server-Side Request Forgery (SSRF) in parisneo/lollms - Expert Insights

CVE ID :CVE-2026-0560 Published : March 29, 2026, 6:16 p.m. | 38 minutes ago Description :A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails to validate user-controlled URLs, allowing attackers to make arbitrary HTTP requests to internal services and cloud metadata endpoints. This vulnerability can lead to internal network access, cloud metadata access, information disclosure, port scanning, and potentially remote code execution. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
March 29, 2026
Attack Vector: network
Impact: SSRF