Vulnerabilities
Vulnerable Software
Lollms:  >> Lollms Web Ui  >> 9.9  Security Vulnerabilities
parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending a specially crafted HTTP request to the /open_file endpoint.
CVSS Score
5.3
EPSS Score
0.016
Published
2025-03-20
A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim into installing ComfyUI. If the victim's device does not have sufficient capacity, this can result in a crash.
CVSS Score
4.4
EPSS Score
0.001
Published
2024-10-29
A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a project or sending a message. The issue impacts the confidentiality and integrity of the information.
CVSS Score
8.1
EPSS Score
0.001
Published
2024-10-29


Contact Us

Shodan ® - All rights reserved