CVE-2026-24478
- EPSS 0.16%
- Veröffentlicht 26.01.2026 23:23:54
- Zuletzt bearbeitet 28.01.2026 15:52:39
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.10.0, a critical Path Traversal vulnerability in the DrupalWiki integration allows a malicious admin (or an...
CVE-2026-24477
- EPSS 0.03%
- Veröffentlicht 26.01.2026 23:22:27
- Zuletzt bearbeitet 28.01.2026 15:59:06
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. If AnythingLLM prior to version 1.10.0 is configured to use Qdrant as the vector database with an API key, this QdrantApiKey c...
CVE-2026-21484
- EPSS 0.05%
- Veröffentlicht 03.01.2026 01:21:39
- Zuletzt bearbeitet 23.02.2026 17:54:38
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery endpoint returns different error messages depe...
CVE-2025-63390
- EPSS 0.04%
- Veröffentlicht 18.12.2025 00:00:00
- Zuletzt bearbeitet 22.01.2026 18:16:44
An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote attackers to enumerate and retrieve detailed inform...
CVE-2024-8248
- EPSS 0.24%
- Veröffentlicht 20.03.2025 10:11:32
- Zuletzt bearbeitet 15.07.2025 15:16:11
A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file read and write in the storage directory. This can result in privilege escalation from manager to admi...
CVE-2024-6842
- EPSS 72.56%
- Veröffentlicht 20.03.2025 10:10:27
- Zuletzt bearbeitet 15.10.2025 13:15:50
In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for ...
CVE-2024-10513
- EPSS 0.28%
- Veröffentlicht 20.03.2025 10:09:51
- Zuletzt bearbeitet 14.07.2025 14:01:04
A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with the 'manager' role to access and manipulate the 'anything...
CVE-2024-8249
- EPSS 0.1%
- Veröffentlicht 20.03.2025 10:09:41
- Zuletzt bearbeitet 15.07.2025 15:17:28
mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the API for the embeddable chat functionality. An attacker can exploit this vulnerability by sending a malformed JSON payload to the A...
CVE-2024-10109
- EPSS 0.13%
- Veröffentlicht 20.03.2025 10:09:27
- Zuletzt bearbeitet 11.07.2025 20:43:39
A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the model's API key and base path, lea...
CVE-2024-7771
- EPSS 0.12%
- Veröffentlicht 20.03.2025 10:08:49
- Zuletzt bearbeitet 15.07.2025 15:12:59
A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an audio file with a very low sample rate causes the functionality responsible for transcribing it to cras...