LoLLMs WEBUI was found to contain two high-severity vulnerabilities affecting core web application functionality. The most severe issue, tracked as CVE-2026-33340, is an unauthenticated server-side request forgery (SSRF) in the POST /api/proxy endpoint that affects all known existing versions. An attacker can abuse the endpoint to force the server to make arbitrary GET requests, potentially reaching internal services, scanning local networks, and retrieving sensitive cloud metadata, including possible AWS or GCP IAM tokens. The flaw is mapped to CWE-306 and CWE-918, with a CVSS 3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, and no patched version was known at publication.
A second critical flaw, CVE-2026-0562, affects parisneo/lollms through an insecure direct object reference (IDOR) in friend request handling. In versions up to 2.2.0, the respond_request() function in backend/routers/friends.py failed to verify that the authenticated user was part of the targeted friendship, allowing any logged-in user to accept or reject another user's friend requests via /api/friends/requests/{friendship_id}. The weakness, mapped to CWE-863, could enable unauthorized actions, privacy violations, and social engineering abuse; unlike the SSRF issue, this bug includes references to a fixing commit and a Huntr report.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Reference material for CVE-2026-0562 included a fixing commit and Huntr advisory, indicating that remediation details were made available for the authorization flaw in parisneo/lollms. The fix addressed missing authorization checks in respond_request() within backend/routers/friends.py.
A critical insecure direct object reference vulnerability, later tracked as CVE-2026-0562, was received by security@huntr.dev. In versions up to 2.2.0, the /api/friends/requests/{friendship_id} endpoint lacked authorization checks, allowing authenticated users to accept or reject other users' friend requests.
A critical unauthenticated server-side request forgery flaw in the /api/proxy endpoint of LoLLMs WEBUI was disclosed, affecting all known existing versions. The issue could let attackers make arbitrary GET requests from the server to access internal services, scan local networks, or retrieve cloud metadata.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.