8.1
CVE-2024-0549
- EPSS 0.82%
- Veröffentlicht 16.04.2024 00:15:07
- Zuletzt bearbeitet 09.07.2025 19:37:14
- Quelle security@huntr.dev
- CVE-Watchlists
- Unerledigt
Relative Path Traversal in mintplex-labs/anything-llm
mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete files and folders within the filesystem, including critical database files such as 'anythingllm.db'. The vulnerability stems from insufficient input validation and normalization in the handling of file and folder deletion requests. Successful exploitation results in the compromise of data integrity and availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mintplexlabs ≫ Anythingllm Version < 1.0.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.82% | 0.524 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@huntr.dev | 8.1 | 2.8 | 5.2 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
CWE-23 Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
https://github.com/mintplex-labs/anything-llm/commit/026849df0224b6a8754f4103530bc015874def62
https://huntr.com/bounties/fcb4001e-0290-4b78-a2f0-91ee5d20cc72