Impact
A flaw has been identified in the sigoden aichat API endpoint defined in src/serve.rs that allows attackers to trigger uncontrolled memory allocation. This vulnerability can be exploited remotely and may enable an attacker to exhaust system resources, resulting in denial of service. The issue is classified under CWE-400 (Unvalidated Input) and CWE-789 (Uncontrolled Memory Allocation).
Affected Systems
The affected vendor is sigoden, product aichat. Versions up to and including 0.30.4 are vulnerable. The specific function impacted within serve.rs is not clearly documented, but the flaw is present in the component API endpoint that processes incoming requests.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. While the EPSS score is not available, the vulnerability has an active published exploit and can be launched remotely. It is not yet listed in CISA KEV. Attackers could use the remote exploitation path to trigger excessive memory allocation and bring the service down. The lack of vendor response underscores the urgency of applying a fix or mitigating controls.
OpenCVE Enrichment