Mintplexlabs

Anythingllm

56 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.09%
  • Veröffentlicht 20.03.2025 10:08:48
  • Zuletzt bearbeitet 15.10.2025 13:15:54

A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint "/embed/:embedId/stream-chat" where user-provided JSON is directly taken to the Prisma library's where clause. An a...

Exploit
  • EPSS 2.83%
  • Veröffentlicht 10.02.2025 19:15:37
  • Zuletzt bearbeitet 09.07.2025 15:11:29

A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library. This vulnerability can lead to arbitrary file write, which can subsequently result i...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 29.10.2024 13:15:10
  • Zuletzt bearbeitet 31.10.2024 15:49:02

mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the ...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 12.08.2024 13:38:26
  • Zuletzt bearbeitet 15.10.2025 13:15:42

An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous attacker, without an account in the application, to import their own databa...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 25.06.2024 11:15:50
  • Zuletzt bearbeitet 15.07.2025 15:38:18

A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the application's failure to limit the size of usernames, enabling attackers to...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 20.06.2024 03:15:09
  • Zuletzt bearbeitet 15.10.2025 13:15:46

In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the response after login (`POST /api/request-token`) and after account creations (`POST /api/admin/users/new`)....

Exploit
  • EPSS 0.12%
  • Veröffentlicht 19.06.2024 06:15:11
  • Zuletzt bearbeitet 15.10.2025 13:15:46

An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows attackers to cause a denial of service (DOS) by shutting down the server through sending invalid upload r...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 12.06.2024 12:15:10
  • Zuletzt bearbeitet 15.07.2025 15:04:32

A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the manager to read, delete, or overwrite the 'anyt...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 06.06.2024 19:16:00
  • Zuletzt bearbeitet 21.11.2024 09:29:00

mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifically, the server can be shut down by sending an invalid upload request. ...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 06.06.2024 19:16:00
  • Zuletzt bearbeitet 21.11.2024 09:29:00

In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their privileges to Administrator. The issue arises from improper input validation when handling HTTP POST ...