Insecure Direct Object Reference in Parisneo Lollms Affects User Friend Request Management
CVE-2026-0562
8.3HIGH
What is CVE-2026-0562?
A vulnerability in Parisneo's Lollms platform allows authenticated users to manipulate and respond to friend requests belonging to others due to inadequate authorization checks in the respond_request() function. This flawed implementation exposes users to potential unauthorized access and privacy breaches, enabling malicious actors to exploit this flaw for social engineering attacks. The vulnerability has been patched in version 2.2.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
parisneo/lollms < 2.2.0
