CVE-2026-10595
published 2026-08-09CVE-2026-10595: A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The…
PriorityP352high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
0.49%
41.3th percentile
A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment checks. URL-encoded dot-dot sequences (`%2e%2e`) bypass Starlette's built-in path normalization and are resolved by Python's `pathlib`, allowing an unauthenticated attacker to read arbitrary files on the server. This issue has been resolved in version 3.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| parisneo | parisneo_lollms | >= unspecified < 3 | 3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
parisneo lollms up to 2.1.0 SPA Catch-All Route backend/routers/ui.py path traversal (EUVD-2026-54864)
vuldb·2026-08-09·CVSS 7.5
CVE-2026-10595 [HIGH] parisneo lollms up to 2.1.0 SPA Catch-All Route backend/routers/ui.py path traversal (EUVD-2026-54864)
A vulnerability was found in parisneo lollms up to 2.1.0. It has been classified as problematic. This impacts an unknown function of the file backend/routers/ui.py of the component SPA Catch-All Route. Performing a manipulation results in path traversal.
This vulnerability is identified as CVE-2026-10595. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`.
ghsa_unreviewed·2026-08-09
CVE-2026-10595 [HIGH] CWE-23 A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`.
A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment checks. URL-encoded dot-dot sequences (`%2e%2e`) bypass Starlette's built-in path normalization and are resolved by Python's `pathlib`, allowing an unauthenticated attacker to read arbitrary files on the server. This issue has been resolved in version 3.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-09
Published