Multipart Boundary Vulnerability in parisneo/lollms-webui
CVE-2025-1451
What is CVE-2025-1451?
A vulnerability exists in the parisneo/lollms-webui v13 related to the handling of multipart boundaries during file uploads. The server fails to impose restrictions on the length and contents of the boundary, permitting attackers to create requests with excessively long or specially crafted boundaries. While an attempt was made to mitigate this issue by blocking hyphen characters, the solution is inadequate, leaving the server still susceptible when other characters, such as '4' or 'a', are utilized. This oversight may result in resource exhaustion and result in denial of service, disrupting normal operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
parisneo/lollms-webui <= unspecified
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
