5.7
CVE-2025-7105
- EPSS 0.26%
- Veröffentlicht 02.02.2026 10:36:24
- Zuletzt bearbeitet 15.04.2026 14:34:27
- CVE-Watchlists
- Unerledigt
Denial of Service via JavaScript Memory Overflow in danny-avila/librechat
A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork` to fork numerous contents rapidly. If the forked content includes a Mermaid graph with a large number of nodes, it can lead to a JavaScript heap out of memory error upon service restart, causing a denial of service. This issue affects the latest version of the product.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerdanny-avila
≫
Produkt
danny-avila/librechat
Version
unspecified
Version <
v0.7.9
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.179 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@huntr.dev | 5.7 | 2.1 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://huntr.com/bounties/e44f0740-48bd-443b-8826-528e6afe9e34
https://github.com/danny-avila/librechat/commit/97a99985fa339db0a21ad63604e0bb8db4442ffc