A vulnerability was found in parisneo lollms up to 2.1.0. It has been classified as problematic. This impacts an unknown function of the file backend/routers/ui.py of the component SPA Catch-All Route. Performing a manipulation results in path traversal.

This vulnerability is identified as CVE-2026-10595. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended.