LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-0558 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 31, 2026

parisneo lollms - Unrestricted File Upload

Published: March 29, 2026Updated: March 31, 2026PoC AvailableRemote Exploitable

Overview

parisneo/lollms <= 2.2.0 contains an unrestricted file upload vulnerability caused by missing authentication on /api/files/extract-text endpoint, letting unauthenticated users upload files causing DoS and information disclosure.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 11.2%(Probability of exploitation in next 30 days)

Impact

Unauthenticated users can upload files causing resource exhaustion, DoS, and potential information disclosure.

Mitigation

Update to the latest version that enforces authentication on /api/files/extract-text endpoint.

Social Media Activity(2 posts)

Offensive Sequence
Offensive Sequence
@offseq
Mar 29, 2026

🚨 HIGH severity: CVE-2026-0558 in parisneo/lollms (≤2.2.0) — /api/files/extract-text allows unauthenticated file uploads, risking DoS & info leaks. Restrict access, enforce auth, and monitor activity. No patch yet. https://radar.offseq.com/threat/cve-2026-0558-cwe-287-improper-authentication-in-p-51fddf90 #OffSeq #Vuln #AppSec

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 29, 2026

🟠 CVE-2026-0558 - High (7.5) A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other file-relate... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-0558/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-0558
Severity
Critical
CVSS Score
9.8
Type
unrestricted_file_upload
Status
confirmed
EPSS
11.2%
Social Posts
2

CWE

  • CWE-287
  • NVD-CWE-noinfo

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

11.2%Probability of exploitation in the next 30 days