Unauthenticated Access Vulnerability in Parisneo's Lollms Version 5.9.0
CVE-2026-1117

8.2HIGH

Key Information:

Vendor

Parisneo

Vendor
CVE Published:
2 February 2026

What is CVE-2026-1117?

In Parisneo's Lollms version 5.9.0, a critical vulnerability exists within the lollms_generation_events.py component, allowing unauthenticated clients to access and manipulate sensitive Socket.IO events. The lack of authentication or authorization checks in functions like add_events enables unauthorized users to initiate resource-heavy processes, potentially causing denial of service and corrupting the application state. Furthermore, the reliance on global state flags for managing the application's state poses additional risks in a multi-client environment, where actions by one client can disrupt the experience for others. This highlights significant flaws in access control and state management, impacting both service availability and data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

parisneo/lollms < 2.0.0

References

CVSS V3.0

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.