Impact
The vulnerability resides in Rowboat's Composio Webhook Endpoint, where an attacker can manipulate the request.text/req.json payload to trigger a denial of service. The flaw allows a remote actor to send crafted payloads that cause the server to overload or crash, impacting availability. This is a buffer or resource exhaustion weakness that can be exercised over the network.
Affected Systems
Rowboat developed by rowboatlabs, versions up to 0.9.1, are affected. The issue is present in the apps/rowboat/app/api/composio/webhook/route.ts file of the Composio Webhook Endpoint component. Any deployment using the legacy Next.js app before the 0.9.2 release contains this vulnerability.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and the exploit is publicly available with no known EPSS data. Since the attack vector is remote and no authentication is required, the risk to any publicly exposed Rowboat instance is significant. The vulnerability is not listed in the CISA KEV catalog, but a public exploit is available, so patching should be prioritized.
OpenCVE Enrichment