Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.2

Parisneo Lollms Software Allows Malicious Code to be Injected

CVE-2026-1116
Summary

A security weakness in the Parisneo Lollms software could allow an attacker to inject malicious code into a user's browser, potentially leading to unauthorized access to accounts or sessions. This is a concern for users of the software, especially if they handle sensitive data. To protect yourself, update the software to version 2.2.0 or later.

Original title
A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack...
Original description
A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the `content` field when deserializing user-provided data. This allows an attacker to inject malicious HTML or JavaScript payloads, which can be executed in the context of another user's browser. Exploitation of this vulnerability can lead to account takeover, session hijacking, or wormable attacks.
nvd CVSS3.0 8.2
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 12 Apr 2026 · Updated: 12 Apr 2026 · First seen: 12 Apr 2026