Impact
The flaw is an infinite loop triggered within the Agent Execution Workflow of bytebot‑ai bytebot 0.0.1. A malicious actor can manipulate this unknown function to force the loop, causing the agent process to consume CPU and memory until it stalls or crashes. The primary impact is a denial of service, as the agent becomes unresponsive and can no longer process legitimate requests. The vulnerability is classified as CWE‐835 (Infinite Loop) and CWE‐404 (Resource Exhaustion).
Affected Systems
Affected software is bytebot‑ai’s bytebot application, version 0.0.1. The component in question is the Agent Execution Workflow; no other versions or related products are mentioned. The maintainer has stopped supporting this release, meaning no official patch or fix will be delivered.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity and the lack of an EPSS score renders the exploitation probability unknown. However, the exploit is publicly available and can be triggered remotely, suggesting that an adversary with network access can cause a DoS. Since the software is unsupported, the risk remains elevated until the product is removed or isolated. The vulnerability is not listed in CISA KEV, but its remote nature and public exploit code increase operational risk for environments that still deploy this version.
OpenCVE Enrichment