Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SSRF in parisneo/lollms-webui
Vulnerability Description
parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST /api/proxy` REST API. Attackers can exploit this vulnerability to abuse the victim server's credentials to access unauthorized web resources by specifying the JSON parameter `{"url":"http://steal.target"}`. Existing security mechanisms such as `forbid_remote_access(lollmsElfServer)`, `lollmsElfServer.config.headless_server_mode`, and `check_access(lollmsElfServer, request.client_id)` do not protect against this vulnerability.
CVSS Information
N/A
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
LoLLMs Web UI 安全漏洞
Vulnerability Description
LoLLMs Web UI是Saifeddine ALOUI个人开发者的一个大型语言与多模态系统的 Web 用户界面。 LoLLMs Web UI V13版本存在安全漏洞,该漏洞源于未验证URL,可能导致服务端请求伪造攻击。
CVSS Information
N/A
Vulnerability Type
N/A