THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-10595 (HIGH 7.5) — A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem pa

[NVD] CVE-2026-10595 (HIGH 7.5) — A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem pa

mednvdPublished 2026-08-09

CVE-2026-10595 CVSS: 7.5 HIGH Published: 2026-08-09T04:17:29.400

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment checks. URL-enc

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-10595