CVE-2025-63390
- EPSS 0.04%
- Veröffentlicht 18.12.2025 00:00:00
- Zuletzt bearbeitet 22.01.2026 18:16:44
An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote attackers to enumerate and retrieve detailed inform...
CVE-2024-8248
- EPSS 0.24%
- Veröffentlicht 20.03.2025 10:11:32
- Zuletzt bearbeitet 15.07.2025 15:16:11
A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file read and write in the storage directory. This can result in privilege escalation from manager to admi...
CVE-2024-6842
- EPSS 77.32%
- Veröffentlicht 20.03.2025 10:10:27
- Zuletzt bearbeitet 15.10.2025 13:15:50
In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for ...
CVE-2024-10513
- EPSS 0.28%
- Veröffentlicht 20.03.2025 10:09:51
- Zuletzt bearbeitet 14.07.2025 14:01:04
A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with the 'manager' role to access and manipulate the 'anything...
CVE-2024-8249
- EPSS 0.1%
- Veröffentlicht 20.03.2025 10:09:41
- Zuletzt bearbeitet 15.07.2025 15:17:28
mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the API for the embeddable chat functionality. An attacker can exploit this vulnerability by sending a malformed JSON payload to the A...
CVE-2024-10109
- EPSS 0.13%
- Veröffentlicht 20.03.2025 10:09:27
- Zuletzt bearbeitet 11.07.2025 20:43:39
A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the model's API key and base path, lea...
CVE-2024-7771
- EPSS 0.12%
- Veröffentlicht 20.03.2025 10:08:49
- Zuletzt bearbeitet 15.07.2025 15:12:59
A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an audio file with a very low sample rate causes the functionality responsible for transcribing it to cras...
CVE-2024-8251
- EPSS 0.09%
- Veröffentlicht 20.03.2025 10:08:48
- Zuletzt bearbeitet 15.10.2025 13:15:54
A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint "/embed/:embedId/stream-chat" where user-provided JSON is directly taken to the Prisma library's where clause. An a...
CVE-2024-13059
- EPSS 55.39%
- Veröffentlicht 10.02.2025 19:15:37
- Zuletzt bearbeitet 09.07.2025 15:11:29
A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library. This vulnerability can lead to arbitrary file write, which can subsequently result i...
CVE-2024-7783
- EPSS 0.13%
- Veröffentlicht 29.10.2024 13:15:10
- Zuletzt bearbeitet 31.10.2024 15:49:02
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the ...