CVE-2024-11171

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 20

Summary

CVE-2024-11171 is an input validation vulnerability affecting danny-avila/librechat in versions prior to 0.7.6. The issue lies in the use of multer middleware for handling multipart file uploads with in-memory storage, which lacks a size limit. This creates an opportunity for attackers to upload excessively large files, resulting in server crashes due to out-of-memory errors. The consequence is a complete denial of service, and the vulnerability can be exploited without any privileges.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share