CVE-2024-1569

HIGH

lollms-webui - Unauthenticated Denial of Service via /open_code_in_vs_code Endpoint

Title source: llm
STIX 2.1

Description

parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authentication by sending repeated HTTP POST requests, leading to the opening of Visual Studio Code or the default folder opener (e.g., File Explorer, xdg-open) multiple times. This can render the host machine unusable by exhausting system resources. The vulnerability is present in the latest version of the software.

Scores

CVSS v3 7.5
EPSS 0.0078
EPSS Percentile 51.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (1)
lollms/lollms-webui 9.1
Published Apr 16, 2024
Tracked Since Feb 18, 2026