Appsmith Denial-of-Service Vulnerability via Unauthorized Restart API Access

Vulnerability

A denial-of-service vulnerability has been identified in Appsmith versions through 1.50. The issue arises from improper access control, allowing users without admin rights to invoke the restart API. This action triggers a server restart within the Appsmith container, causing a disruption by repeatedly restarting the server. The vulnerability does not lead to data loss or unauthorized code execution, but can be exploited continuously to cause service interruptions.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the Appsmith server to restart repeatedly and disrupt service.

Remediation

Users can upgrade to Appsmith version 1.51 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.7
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.