Unauthenticated Access Vulnerability in Parisneo's Lollms Version 5.9.0
CVE-2026-1117
What is CVE-2026-1117?
In Parisneo's Lollms version 5.9.0, a critical vulnerability exists within the lollms_generation_events.py component, allowing unauthenticated clients to access and manipulate sensitive Socket.IO events. The lack of authentication or authorization checks in functions like add_events enables unauthorized users to initiate resource-heavy processes, potentially causing denial of service and corrupting the application state. Furthermore, the reliance on global state flags for managing the application's state poses additional risks in a multi-client environment, where actions by one client can disrupt the experience for others. This highlights significant flaws in access control and state management, impacting both service availability and data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
parisneo/lollms < 2.0.0
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
