Impact
The vulnerability exists in the updateComponents function of the basic_functions.ts file within the Update Components component. It allows an attacker to manipulate input in a manner that causes excessive CPU or memory consumption, potentially looping or holding resources indefinitely. The weakness aligns with CWE-400 (Resource Exhaustion) and CWE-404 (Improper Resource Shutdown or Release), which can lead to degraded performance or outright crashes when the application stalls or becomes unresponsive.
Affected Systems
Versions 0.9 and 0.9.1 of the a2ui project are vulnerable. The project’s repository indicates no official patch has been released yet, leaving all deployed instances of these versions at risk. The problematic endpoint can be triggered remotely, and no authentication requirements are documented.
Risk and Exploitability
The CVSS score of 5.3 signals a moderate severity, while the EPSS score of less than 1% suggests a low probability of immediate exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the attack vector is remote, any exposed installation is potentially vulnerable, and an exploit could consume system resources to the point of denial of service or crash. Although no active exploit is known, the possibility of disruption should be considered when planning defenses.
OpenCVE Enrichment