CVE-2026-0558
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the /api/files/extract-text endpoint. This endpoint does not enforce authentication, unlike other file-related endpoints, and lacks the Depends(getcurrentactive_user) dependency. This issue can lead to denial of service (DoS) through resource exhaustion, information disclosure, and violation of the application's documented security policies.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://huntr.com/bounties/0a722001-89ce-4c91-b6a6-a55ee5ba2113, https://github.com/parisneo/lollms/commit/a6625dc83786ff21d109b0d545ca61b770607ef3