Description
A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Error leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A flaw resides in the waitForCallback function of Gitlawb openclaude’s xAI OAuth Callback Handler, where an attacker can manipulate the Error argument to trigger a denial of service. The underlying weakness maps to CWE-404, indicating that the application fails to properly shut down or release a resource, allowing repeated or abnormal requests to overwhelm the service and halt normal operation.

Affected Systems

The vulnerability affects Gitlawb openclaude versions up to 0.30.0. openclaude instance, the waitForCallback routine may be invoked with a crafted Error parameter, leading to service disruption for all users of that instance.

Risk and Exploitability

The CVSS score of 5.3, and the issue does not appear in the CISA KEV catalog, yet the exploit is publicly available and remote exploitation is possible. The EPSS score of < 1% indicates a very low probability of real-world exploitation. The likely attack vector is an external OAuth callback that supplies a tampered Error field; if an attacker convinces users or applications to perform such requests, they can trigger successive DoS events.

Generated by OpenCVE AI on September 15, 2026 at 15:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a newer version of Gitlawb openclaude (>= 0.31.0) argument in waitForCallback to prevent malformed inputs.
  • As a temporary measure, restrict or disable the xAI OAuth Callback Endpoint from external untrusted sources until a fix is applied.
  • Implement input validation to reject malformed Error arguments before processing in the waitForCallback routine.

Generated by OpenCVE AI on September 15, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Error leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Title Gitlawb openclaude xAI OAuth Callback xaiOAuthCallback.ts waitForCallback denial of service
First Time appeared Gitlawb
Gitlawb openclaude
Weaknesses CWE-404
CPEs cpe:2.3:a:gitlawb:openclaude:*:*:*:*:*:*:*:*
Vendors & Products Gitlawb
Gitlawb openclaude
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Gitlawb Openclaude
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T14:20:38.325Z

Reserved: 2026-09-13T09:37:12.669Z

Link: CVE-2026-90712

cve-icon Vulnrichment

Updated: 2026-09-14T14:20:34.385Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T12:17:51.223

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:45:19Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release