← Späť na vyhľadávanie CVE

CVE-2026-1116

lollms

Popis

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the `content` field when deserializing user-provided data. This allows an attacker to inject malicious HTML or JavaScript payloads, which can be executed in the context of another user-s browser. Exploitation of this vulnerability can lead to account takeover, session hijacking, or wormable attacks.

CVSS 8.2EPSS 0.258%Riziko 0.84
Zobraziť zdroj
Zverejnené
2026-04-12 03:16:07
Dotknuté verzie
<2.2.0
Typ
Package
Vektor
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N