parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authentication by sending repeated HTTP POST requests, leading to the opening of Visual Studio Code or the default folder opener (e.g., File Explorer, xdg-open) multiple times. This can render the host machine unusable by exhausting system resources. The vulnerability is present in the latest version of the software.
References
Link | Resource |
---|---|
https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149 | Patch |
https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e | Exploit Third Party Advisory |
https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149 | Patch |
https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e | Exploit Third Party Advisory |
Configurations
History
07 Jul 2025, 15:52
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
References | () https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149 - Patch | |
References | () https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:lollms:lollms-webui:9.1:*:*:*:*:*:*:* | |
First Time |
Lollms
Lollms lollms-webui |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
21 Nov 2024, 08:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149 - | |
References | () https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e - |
16 Apr 2024, 13:24
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
16 Apr 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-16 00:15
Updated : 2025-07-07 15:52
NVD link : CVE-2024-1569
Mitre link : CVE-2024-1569
CVE.ORG link : CVE-2024-1569
JSON object : View
Products Affected
lollms
- lollms-webui
CWE