VYPR
High severity7.5NVD Advisory· Published Apr 16, 2024· Updated Jun 17, 2026

CVE-2024-1569

CVE-2024-1569

Description

parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the /open_code_in_vs_code and similar endpoints without authentication by sending repeated HTTP POST requests, leading to the opening of Visual Studio Code or the default folder opener (e.g., File Explorer, xdg-open) multiple times. This can render the host machine unusable by exhausting system resources. The vulnerability is present in the latest version of the software.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Lollms/Lollms3 versions
    cpe:2.3:a:lollms:lollms-webui:9.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:lollms:lollms-webui:9.1:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.