High severity7.5NVD Advisory· Published Aug 9, 2026
CVE-2026-10595
CVE-2026-10595
Description
A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in backend/routers/ui.py. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment checks. URL-encoded dot-dot sequences (%2e%2e) bypass Starlette's built-in path normalization and are resolved by Python's pathlib, allowing an unauthenticated attacker to read arbitrary files on the server. This issue has been resolved in version 3.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.