Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-33340 PoC — LoLLMs WEBUI 安全漏洞

Source
Associated Vulnerability
Title:LoLLMs WEBUI 安全漏洞 (CVE-2026-33340)
Description:LoLLMs WEBUI是Saifeddine ALOUI个人开发者的一个支持多模型和多模态集成的大模型Web用户界面。 LoLLMs WEBUI存在安全漏洞,该漏洞源于/api/proxy端点允许未经验证的用户强制服务器发起任意GET请求,可能导致访问内部服务、扫描本地网络或泄露敏感云元数据。
Description
LoLLMs WEBUI contains a server-side request forgery caused by unauthenticated access to the /api/proxy endpoint, letting attackers force the server to make arbitrary GET requests, exploit requires no authentication.
File Snapshot

id: CVE-2026-33340 info: name: LoLLMs WEBUI - Server-Side Request Forgery author: theamanrawat ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.