Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2q3x-64cr-5mp5

Опубликовано: 31 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the /api/memories endpoint. The key and value parameters accept arbitrarily large inputs without proper validation, leading to a null pointer error in the Rust-based backend when excessively large values are submitted. This results in the inability to create new memories, impacting the stability of the service.

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the /api/memories endpoint. The key and value parameters accept arbitrarily large inputs without proper validation, leading to a null pointer error in the Rust-based backend when excessively large values are submitted. This results in the inability to create new memories, impacting the stability of the service.

EPSS

Процентиль: 21%
0.00069
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key` and `value` parameters accept arbitrarily large inputs without proper validation, leading to a null pointer error in the Rust-based backend when excessively large values are submitted. This results in the inability to create new memories, impacting the stability of the service.

CVSS3: 5.4
fstec
6 месяцев назад

Уязвимость платформы на базе искуственного интеллекта LibreChat, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 21%
0.00069
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-400