Περιγραφή
A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the `content` field when deserializing user-provided data. This allows an attacker to inject malicious HTML or JavaScript payloads, which can be executed in the context of another user-s browser. Exploitation of this vulnerability can lead to account takeover, session hijacking, or wormable attacks.
CVSS 8.2EPSS 0.258%Κίνδυνος 0.84
Προβολή πηγής- Δημοσίευση
- 2026-04-12 03:16:07
- Επηρεαζόμενες εκδόσεις
- <2.2.0
- Τύπος
- Package
- Διάνυσμα
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N