漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Denial of Service via JavaScript Memory Overflow in danny-avila/librechat
Vulnerability Description
A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork` to fork numerous contents rapidly. If the forked content includes a Mermaid graph with a large number of nodes, it can lead to a JavaScript heap out of memory error upon service restart, causing a denial of service. This issue affects the latest version of the product.
CVSS Information
N/A
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
LibreChat 资源管理错误漏洞
Vulnerability Description
LibreChat是LibreChat开源的一个免费、高度可定制的统一 AI 对话平台,能够在一个界面中聚合并运行来自任意厂商的大模型。 LibreChat存在资源管理错误漏洞,该漏洞源于/api/convos/fork中无限制的Fork函数可能被滥用以快速分叉大量内容,当内容包含具有大量节点的Mermaid图时,可能引发拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A