Impact
A flaw resides in the waitForCallback function of Gitlawb openclaude’s xAI OAuth Callback Handler, where an attacker can manipulate the Error argument to trigger a denial of service. The underlying weakness maps to CWE-404, indicating that the application fails to properly shut down or release a resource, allowing repeated or abnormal requests to overwhelm the service and halt normal operation.
Affected Systems
The vulnerability affects Gitlawb openclaude versions up to 0.30.0. openclaude instance, the waitForCallback routine may be invoked with a crafted Error parameter, leading to service disruption for all users of that instance.
Risk and Exploitability
The CVSS score of 5.3, and the issue does not appear in the CISA KEV catalog, yet the exploit is publicly available and remote exploitation is possible. The EPSS score of < 1% indicates a very low probability of real-world exploitation. The likely attack vector is an external OAuth callback that supplies a tampered Error field; if an attacker convinces users or applications to perform such requests, they can trigger successive DoS events.
OpenCVE Enrichment