PT-2024-5517 · Microsoft · Visual Studio Code
Published
2024-02-15
·
Updated
2025-07-07
·
CVE-2024-1569
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
parisneo/lollms-webui (affected versions not specified)
Description
The issue is related to uncontrolled resource consumption, allowing attackers to exploit the "/open code in vs code" and similar endpoints without authentication by sending repeated HTTP POST requests. This can lead to the opening of Visual Studio Code or the default folder opener multiple times, exhausting system resources and rendering the host machine unusable.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Visual Studio Code