LoLLMs WEBUI contains a server-side request forgery caused by unauthenticated access to the /api/proxy endpoint, letting attackers force the server to make arbitrary GET requests, exploit requires no authentication.
id: CVE-2026-33340
info:
name: LoLLMs WEBUI - Server-Side Request Forgery
author: theamanrawat
...