CVE-2025-1451

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
Updated: Mar 27, 2025
CWE ID 400

Summary

CVE-2025-1451 is a vulnerability affecting parisneo/lollms-webui version 13. The issue stems from the server's failure to limit or validate the length and characters of multipart boundaries in file uploads. An attacker can exploit this vulnerability by crafting requests with excessively long boundaries, ultimately leading to resource exhaustion and a denial of service (DoS) attack. Although a patch was attempted in commit 483341bb, which restricted the use of hyphens in multipart boundaries, it proves insufficient. Attackers can bypass this restriction by using other characters, such as '4' or 'a', to cause resource exhaustion and service unavailability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share