Executive brief
Vrite is an open-source content management and editing platform used to create and manage digital documents. Versions prior to 0.3.0 contain a flaw where an authenticated administrator can trigger unbounded resource allocation on the server without any rate limiting or throttling controls. An attacker with admin credentials could exploit this to exhaust server memory or CPU, causing the application to slow down or become unavailable to legitimate users.
Technical details
The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) in the @vrite/sdk npm package. The root cause involves insufficient resource consumption controls in API endpoints accessible to authenticated users with high privileges (administrator role). An attacker with admin-level access can make requests that allocate unbounded resources without hitting rate limits, throttling mechanisms, or resource caps. This enables denial-of-service conditions by exhausting available server resources. The vulnerability was patched in version 0.3.0, as indicated by commit 1877683 which introduced CORS configuration improvements and other architectural changes. No network-level authentication bypass is required; exploitation requires valid admin credentials.
Affected products
- Vrite @vrite/sdk before 0.3.0
Timeline
- 2023-10-13: disclosed: Vulnerability published on GitHub Advisory Database and NVD
- 2023-10-10: patched: Fix released in version 0.3.0