id: PYSEC-2026-2198 published: "2026-03-29T18:16:13.250Z" modified: "2026-07-13T05:49:44.076062Z" aliases: - CVE-2026-0558 details: A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other file-related endpoints, and lacks the `Depends(get_current_active_user)` dependency. This issue can lead to denial of service (DoS) through resource exhaustion, information disclosure, and violation of the application's documented security policies. affected: - package: name: lollms ecosystem: PyPI purl: pkg:pypi/lollms ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 2.1.1 versions: - 1.1.10 - 1.1.11 - 1.1.12 - 1.1.13 - 1.1.14 - 1.1.15 - 1.1.16 - 1.1.17 - 1.1.18 - 1.1.19 - 1.1.20 - 1.1.21 - 1.1.22 - 1.1.25 - 1.1.26 - 1.1.27 - 1.1.28 - 1.1.29 - 1.1.3 - 1.1.30 - 1.1.31 - 1.1.32 - 1.1.33 - 1.1.34 - 1.1.35 - 1.1.36 - 1.1.37 - 1.1.38 - 1.1.45 - 1.1.46 - 1.1.47 - 1.1.48 - 1.1.49 - 1.1.5 - 1.1.50 - 1.1.51 - 1.1.52 - 1.1.53 - 1.1.55 - 1.1.56 - 1.1.57 - 1.1.58 - 1.1.59 - 1.1.6 - 1.1.60 - 1.1.61 - 1.1.62 - 1.1.63 - 1.1.64 - 1.1.65 - 1.1.66 - 1.1.67 - 1.1.68 - 1.1.69 - 1.1.7 - 1.1.70 - 1.1.71 - 1.1.73 - 1.1.74 - 1.1.75 - 1.1.76 - 1.1.77 - 1.1.78 - 1.1.79 - 1.1.80 - 1.1.82 - 1.1.83 - 1.1.84 - 1.1.85 - 1.1.86 - 1.1.9 - 1.1.90 - 1.1.91 - 1.1.92 - 1.2.0 - 1.2.1 - 1.2.10 - 1.2.11 - 1.2.12 - 1.2.14 - 1.2.3 - 1.2.4 - 1.2.6 - 1.2.7 - 1.2.8 - 1.2.9 - 2.0.0 - 2.0.1 - 2.0.10 - 2.0.11 - 2.0.12 - 2.0.13 - 2.0.14 - 2.0.15 - 2.0.16 - 2.0.17 - 2.0.18 - 2.0.19 - 2.0.2 - 2.0.20 - 2.0.21 - 2.0.22 - 2.0.23 - 2.0.24 - 2.0.25 - 2.0.26 - 2.0.27 - 2.0.28 - 2.0.3 - 2.0.30 - 2.0.31 - 2.0.32 - 2.0.4 - 2.0.5 - 2.0.6 - 2.0.8 - 2.0.9 - 2.1.0 ecosystem_specific: {} references: - type: REPORT url: https://huntr.com/bounties/0a722001-89ce-4c91-b6a6-a55ee5ba2113 - type: FIX url: https://github.com/parisneo/lollms/commit/a6625dc83786ff21d109b0d545ca61b770607ef3 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H