CVE Explorer
CVE-2026-33340
LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all known existing versions of `lollms-webui`. The `@router.post("/api/proxy")` endpoint allows unauthenticated attackers to force the server into making arbitrary GET requests. This can be exploited to access internal services, scan local networks, or exfiltrate sensitive cloud metadata (e.g., AWS/GCP IAM tokens). As
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cd5a3c037f3cc977ff2f73ff473d0d1e857f2adfbdabfd332000092ac599a7e6 · sha256:1ae9353a2b04d0e9… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cd5a3c037f3cc977ff2f73ff473d0d1e857f2adfbdabfd332000092ac599a7e6 · sha256:1ae9353a2b04d0e9… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"lollms-webui","vendor":"ParisNeo","versions":[{"status":"affected","version":"<= 8c5dcef63d847bb3d027ec74915d8fe4afd3014e"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:cd5a3c037f3cc977ff2f73ff473d0d1e857f2adfbdabfd332000092ac599a7e6 · sha256:1ae9353a2b04d0e9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:cd5a3c037f3cc977ff2f73ff473d0d1e857f2adfbdabfd332000092ac599a7e6 · sha256:1ae9353a2b04d0e9… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cd5a3c037f3cc977ff2f73ff473d0d1e857f2adfbdabfd332000092ac599a7e6 · sha256:1ae9353a2b04d0e9… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:cd5a3c037f3cc977ff2f73ff473d0d1e857f2adfbdabfd332000092ac599a7e6 · sha256:1ae9353a2b04d0e9… · /containers/cna/problemTypes/1/descriptions/0
Source references
3 source assertions{"name":"https://github.com/ParisNeo/lollms-webui/blob/8c5dcef63d847bb3d027ec74915d8fe4afd3014e/lollms/server/endpoints/lollms_apps.py#L443-L450","tags":["x_refsource_MISC"],"url":"https://github.com/ParisNeo/lollms-webui/blob/8c5dcef63d847bb3d027ec74915d8fe4afd3014e/lollms/server/endpoints/lollms_apps.py#L443-L450"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cd5a3c037f3cc977ff2f73ff473d0d1e857f2adfbdabfd332000092ac599a7e6 · sha256:1ae9353a2b04d0e9… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/ParisNeo/lollms-webui/security/advisories/GHSA-mcwr-5469-pxj4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cd5a3c037f3cc977ff2f73ff473d0d1e857f2adfbdabfd332000092ac599a7e6 · sha256:1ae9353a2b04d0e9… · /containers/adp/0/references/0
{"name":"https://github.com/ParisNeo/lollms-webui/security/advisories/GHSA-mcwr-5469-pxj4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/ParisNeo/lollms-webui/security/advisories/GHSA-mcwr-5469-pxj4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:cd5a3c037f3cc977ff2f73ff473d0d1e857f2adfbdabfd332000092ac599a7e6 · sha256:1ae9353a2b04d0e9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.