PT-2026-27456 · Unknown · Lollms-Webui

Regaan

·

Published

2026-03-24

·

Updated

2026-03-24

·

CVE-2026-33340

CVSS v3.1

9.1

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions LoLLMs WEBUI (affected versions not specified)
Description LoLLMs WEBUI provides the web user interface for Lord of Large Language and Multi modal Systems. A Server-Side Request Forgery (SSRF) issue exists in all known versions of lollms-webui. The /api/proxy endpoint allows unauthenticated attackers to make arbitrary GET requests, potentially enabling access to internal services, local network scanning, and the exfiltration of sensitive cloud metadata.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-33340

Affected Products

Lollms-Webui