Unauthenticated Access Vulnerability in Parisneo's Lollms Version 5.9.0
CVE-2026-1117

8.2HIGH

Key Information:

Vendor

Parisneo

Vendor
CVE Published:
2 February 2026

What is CVE-2026-1117?

In Parisneo's Lollms version 5.9.0, a critical vulnerability exists within the lollms_generation_events.py component, allowing unauthenticated clients to access and manipulate sensitive Socket.IO events. The lack of authentication or authorization checks in functions like add_events enables unauthorized users to initiate resource-heavy processes, potentially causing denial of service and corrupting the application state. Furthermore, the reliance on global state flags for managing the application's state poses additional risks in a multi-client environment, where actions by one client can disrupt the experience for others. This highlights significant flaws in access control and state management, impacting both service availability and data integrity.

Affected Version(s)

parisneo/lollms < 2.0.0

References

CVSS V3.0

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.