CVE-2026-0560 | parisneo lollms up to 2.1.x export-content _download_image_to_temp server-side request forgery (EUVD-2026-17037)
A vulnerability was found in parisneo lollms up to 2.1.x. It has been classified as critical. Affected by this issue is the function _download_image_to_temp of the file /api/files/export-content. Performing a manipulation results in server-side request forgery.
This vulnerability is known as CVE-2026-0560. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.