LoLLMs是Saifeddine ALOUI个人开发者的一个大型语言与多模态系统。 LoLLMs 2.2.0之前版本存在安全漏洞,该漏洞源于create_post函数未对用户提供的内容进行清理,可能导致存储型跨站脚本攻击,进而引发账户接管、会话劫持或蠕虫式攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| parisneo | parisneo/lollms | unspecified ~ 2.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | parisneo/lollms < 2.2.0 contains a stored XSS caused by unsanitized user input in create_post function in backend/routers/social/__init__.py, letting attackers inject malicious scripts executed in user browsers, exploit requires crafted post submission. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-1115.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet