Unauthenticated Access Vulnerability in Parisneo's Lollms Version 5.9.0
CVE-2026-1117
What is CVE-2026-1117?
In Parisneo's Lollms version 5.9.0, a critical vulnerability exists within the lollms_generation_events.py component, allowing unauthenticated clients to access and manipulate sensitive Socket.IO events. The lack of authentication or authorization checks in functions like add_events enables unauthorized users to initiate resource-heavy processes, potentially causing denial of service and corrupting the application state. Furthermore, the reliance on global state flags for managing the application's state poses additional risks in a multi-client environment, where actions by one client can disrupt the experience for others. This highlights significant flaws in access control and state management, impacting both service availability and data integrity.
Affected Version(s)
parisneo/lollms < 2.0.0
