Ad

CVE-2026-33340

CRITICAL CVSS 3.1: 9.1
Updated Mar 24, 2026
LoLLMs
Parameter Value
CVSS 9.1 (CRITICAL)
Type CWE-306 (Missing Authentication for Critical Function), CWE-918 (Server-Side Request Forgery (SSRF))
Vendor LoLLMs
Public PoC No

LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all known existing versions of `lollms-webui`. The `@router.post("/api/proxy")` endpoint allows unauthenticated attackers to force the server into making arbitrary GET requests.

This can be exploited to access internal services, scan local networks, or exfiltrate sensitive cloud metadata (e.g., AWS/GCP IAM tokens). As of time of publication, no known patched versions are available.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1