CVE-2024-1569

parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authentication by sending repeated HTTP POST requests, leading to the opening of Visual Studio Code or the default folder opener (e.g., File Explorer, xdg-open) multiple times. This can render the host machine unusable by exhausting system resources. The vulnerability is present in the latest version of the software.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lollms:lollms-webui:9.1:*:*:*:*:*:*:*

History

07 Jul 2025, 15:52

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:lollms:lollms-webui:9.1:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Lollms lollms-webui
Lollms
References () https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149 - () https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149 - Patch
References () https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e - () https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e - Exploit, Third Party Advisory

Information

Published : 2024-04-16 00:15

Updated : 2025-07-07 15:52


NVD link : CVE-2024-1569

Mitre link : CVE-2024-1569

CVE.ORG link : CVE-2024-1569


JSON object : View

Products Affected

lollms

  • lollms-webui
CWE
CWE-400

Uncontrolled Resource Consumption

NVD-CWE-noinfo