VYPR

lollms-webui

by LoLLMs WEBUI

CVEs (1)

  • CVE-2026-33340CriMar 24, 2026
    risk 0.61cvss 9.1epss 0.22

    LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all known existing versions of `lollms-webui`. The `@router.post("/api/proxy")` endpoint allows…