A vulnerability labeled as problematic has been found in parisneo lollms. This affects an unknown part of the file /api/prompts/share of the component MessageContentRenderer. Such manipulation of the argument prompt_content leads to cross site scripting.

This vulnerability is documented as CVE-2026-12228. The attack can be executed remotely. There is not any exploit available.