CVE Explorer
CVE-2026-1116
A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the `content` field when deserializing user-provided data. This allows an attacker to inject malicious HTML or JavaScript payloads, which can be executed in the context of another user's browser. Exploitation of this vulnerability can lead to account takeover, sessi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"parisneo/lollms","vendor":"parisneo","versions":[{"lessThan":"2.2.0","status":"affected","version":"unspecified","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2ffaf76b8db82ecc0064c3d3599e7c4c32a9f084b476df86c4f34361d14c32b4 · sha256:319d370e45c5552c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","version":"3.0"},"metric_type":"cvssV3_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2ffaf76b8db82ecc0064c3d3599e7c4c32a9f084b476df86c4f34361d14c32b4 · sha256:319d370e45c5552c… · /containers/cna/metrics/0/cvssV3_0
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2ffaf76b8db82ecc0064c3d3599e7c4c32a9f084b476df86c4f34361d14c32b4 · sha256:319d370e45c5552c… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://github.com/parisneo/lollms/commit/9767b882dbc893c388a286856beeaead69b8292a"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2ffaf76b8db82ecc0064c3d3599e7c4c32a9f084b476df86c4f34361d14c32b4 · sha256:319d370e45c5552c… · /containers/cna/references/1
{"url":"https://huntr.com/bounties/d3d076a7-2a51-4e07-8d0e-91e28e76788e"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2ffaf76b8db82ecc0064c3d3599e7c4c32a9f084b476df86c4f34361d14c32b4 · sha256:319d370e45c5552c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.