{"id":"CVE-2024-1569","summary":"Uncontrolled Resource Consumption in parisneo/lollms-webui","details":"parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authentication by sending repeated HTTP POST requests, leading to the opening of Visual Studio Code or the default folder opener (e.g., File Explorer, xdg-open) multiple times. This can render the host machine unusable by exhausting system resources. The vulnerability is present in the latest version of the software.","modified":"2026-08-12T03:51:28.856134534Z","published":"2024-04-16T00:00:14.761Z","database_specific":{"cna_assigner":"@huntr_ai","cwe_ids":["CWE-400"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1569.json"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/369d1694-47e4-49bc-bb35-931ce4a5148e"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1569.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1569"},{"type":"FIX","url":"https://github.com/parisneo/lollms-webui/commit/354cf766835396b7fc0d5105ed3b77572a653149"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/parisneo/lollms-webui","events":[{"introduced":"f87df9e0754ad9b497a630740338f8f2c98cb0a1"},{"fixed":"354cf766835396b7fc0d5105ed3b77572a653149"}],"database_specific":{"cpe":"cpe:2.3:a:lollms:lollms-webui:9.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"9.1"},{"last_affected":"9.1"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["9.1","v9.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-1569.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}