Executive brief
Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
Affected products
- PyPI lollms
Junglewise Threat Intelligence
CVE-2025-6386 · Severity: low · CVSS 3 · Published 2026-07-07
Technologies: lollms (PyPI). Vendors: PyPI.
Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function