CVE-2024-1569

parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authentication by sending repeated HTTP POST requests, leading to the opening of Visual Studio Code or the default folder opener (e.g., File Explorer, xdg-open) multiple times. This can render the host machine unusable by exhausting system resources. The vulnerability is present in the latest version of the software.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lollms:lollms-webui:9.1:*:*:*:*:*:*:*

History

07 Jul 2025, 15:52

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149 - () https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149 - Patch
References () https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e - () https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e - Exploit, Third Party Advisory
CPE cpe:2.3:a:lollms:lollms-webui:9.1:*:*:*:*:*:*:*
First Time Lollms
Lollms lollms-webui
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 7.5

21 Nov 2024, 08:50

Type Values Removed Values Added
References () https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149 - () https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149 -
References () https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e - () https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e -

16 Apr 2024, 13:24

Type Values Removed Values Added
Summary
  • (es) parisneo/lollms-webui es vulnerable a un ataque de denegación de servicio (DoS) debido al consumo incontrolado de recursos. Los atacantes pueden explotar `/open_code_in_vs_code` y endpoints similares sin autenticación enviando solicitudes HTTP POST repetidas, lo que lleva a la apertura de Visual Studio Code o del abridor de carpeta predeterminado (por ejemplo, Explorador de archivos, xdg-open) varias veces. Esto puede inutilizar la máquina host al agotar los recursos del sistema. La vulnerabilidad está presente en la última versión del software.

16 Apr 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-16 00:15

Updated : 2025-07-07 15:52


NVD link : CVE-2024-1569

Mitre link : CVE-2024-1569

CVE.ORG link : CVE-2024-1569


JSON object : View

Products Affected

lollms

  • lollms-webui
CWE
CWE-400

Uncontrolled Resource Consumption

NVD-CWE-noinfo