Mintplexlabs

Anythingllm

63 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.26%
  • Veröffentlicht 12.08.2024 13:38:26
  • Zuletzt bearbeitet 15.10.2025 13:15:42

An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous attacker, without an account in the application, to import their own databa...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 25.06.2024 11:15:50
  • Zuletzt bearbeitet 15.07.2025 15:38:18

A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the application's failure to limit the size of usernames, enabling attackers to...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 20.06.2024 03:15:09
  • Zuletzt bearbeitet 15.10.2025 13:15:46

In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the response after login (`POST /api/request-token`) and after account creations (`POST /api/admin/users/new`)....

Exploit
  • EPSS 0.12%
  • Veröffentlicht 19.06.2024 06:15:11
  • Zuletzt bearbeitet 15.10.2025 13:15:46

An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows attackers to cause a denial of service (DOS) by shutting down the server through sending invalid upload r...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 12.06.2024 12:15:10
  • Zuletzt bearbeitet 15.07.2025 15:04:32

A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the manager to read, delete, or overwrite the 'anyt...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 06.06.2024 19:16:00
  • Zuletzt bearbeitet 21.11.2024 09:29:00

mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifically, the server can be shut down by sending an invalid upload request. ...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 06.06.2024 19:16:00
  • Zuletzt bearbeitet 21.11.2024 09:29:00

In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their privileges to Administrator. The issue arises from improper input validation when handling HTTP POST ...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 06.06.2024 19:16:00
  • Zuletzt bearbeitet 21.11.2024 09:29:00

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users with manager or admin roles, processes uploaded links through an internal Collector API using a headl...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 06.06.2024 19:15:59
  • Zuletzt bearbeitet 21.11.2024 09:28:55

A stored Cross-Site Scripting (XSS) vulnerability exists in the mintplex-labs/anything-llm application, affecting versions up to and including the latest before 1.0.0. The vulnerability arises from the application's failure to properly sanitize and v...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 06.06.2024 19:15:59
  • Zuletzt bearbeitet 21.11.2024 09:28:54

A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-token` endpoint. The vulnerability arises from improper handling of values...