CVE-2024-11171
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 20
Summary
CVE-2024-11171 is an input validation vulnerability affecting danny-avila/librechat in versions prior to 0.7.6. The issue lies in the use of multer middleware for handling multipart file uploads with in-memory storage, which lacks a size limit. This creates an opportunity for attackers to upload excessively large files, resulting in server crashes due to out-of-memory errors. The consequence is a complete denial of service, and the vulnerability can be exploited without any privileges.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.