9.6
/ 10
CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Description
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` function within `backend/routers/social/__init__.py`, where user-provided content is directly assigned to the `DBPost` model without sanitization. This allows attackers to inject and store malicious JavaScript, which is executed in the browsers of users viewing the Home Feed, including administrators. This can lead to account takeover, session hijacking, and wormable attacks. The issue is resolved in version 2.2.0.
AI Analysis
Stored Cross-Site Scripting (XSS) vulnerability in the social feature of lollms, allowing attackers to inject and store malicious JavaScript
Basic Information
ID
CVE-2026-1115
Source
@huntr_ai
Published
Apr 10, 2026 at 06:23
Modified
Apr 10, 2026 at 13:01
Affected Product
Vendor
parisneo
Product
parisneo/lollms
Version
unspecified
Affected Versions
parisneo parisneo/lollms unspecified
CWE Classification
AI Assessment
AI Score
9.6 / 10
AI Severity
Critical
Vendor
parisneo
Product
lollms
Version
prior to 2.2.0