THREAT OPS › Threat News › [NVD] CVE-2026-10595 (HIGH 7.5) — A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem pa
[NVD] CVE-2026-10595 (HIGH 7.5) — A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem pa
CVE-2026-10595 CVSS: 7.5 HIGH Published: 2026-08-09T04:17:29.400
A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment checks. URL-enc
Indicators of compromise
- CVE-2026-10595cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-10595