Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-53977

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Aug 06, 2026
Vendor unknown

Description

OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express route handler chain. Attackers can exploit the route registration order in bootstrap-runtime.js to reach the shutdown handler before auth middleware executes, causing denial of service to all active AI coding sessions and locking out legitimate remote users regardless of whether UI_PASSWORD is configured.

References