CVE-2024-3149
- EPSS 0.13%
- Veröffentlicht 06.06.2024 19:16:00
- Zuletzt bearbeitet 21.11.2024 09:29:00
A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users with manager or admin roles, processes uploaded links through an internal Collector API using a headl...
CVE-2024-3110
- EPSS 0.22%
- Veröffentlicht 06.06.2024 19:15:59
- Zuletzt bearbeitet 21.11.2024 09:28:55
A stored Cross-Site Scripting (XSS) vulnerability exists in the mintplex-labs/anything-llm application, affecting versions up to and including the latest before 1.0.0. The vulnerability arises from the application's failure to properly sanitize and v...
CVE-2024-3102
- EPSS 0.17%
- Veröffentlicht 06.06.2024 19:15:59
- Zuletzt bearbeitet 21.11.2024 09:28:54
A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-token` endpoint. The vulnerability arises from improper handling of values...
CVE-2024-3152
- EPSS 0.13%
- Veröffentlicht 06.06.2024 18:15:17
- Zuletzt bearbeitet 15.10.2025 13:15:42
mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit these vulnerabilities to escalate privileges from a default user role to an admin role, read and delet...
CVE-2024-3104
- EPSS 6.58%
- Veröffentlicht 06.06.2024 18:15:17
- Zuletzt bearbeitet 21.11.2024 09:28:54
A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment variables. Attackers can exploit this vulnerability by injecting arbitrary environment variables via the `POST /api/system/update-env` ...
CVE-2024-3033
- EPSS 0.15%
- Veröffentlicht 06.06.2024 18:15:17
- Zuletzt bearbeitet 21.11.2024 09:28:43
An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the VectorDB, includ...
CVE-2024-4084
- EPSS 0.08%
- Veröffentlicht 05.06.2024 00:15:09
- Zuletzt bearbeitet 21.11.2024 09:42:09
A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of mintplex-labs/anything-llm, allowing attackers to bypass the official fix intended to restrict access to intranet IP addresses and protocols. Despite efforts to filter...
CVE-2024-4286
- EPSS 0.1%
- Veröffentlicht 26.05.2024 23:15:21
- Zuletzt bearbeitet 21.11.2024 09:42:32
Mintplex-Labs' anything-llm application is vulnerable to improper neutralization of special elements used in an expression language statement, identified in the commit id `57984fa85c31988b2eff429adfc654c46e0c342a`. The vulnerability arises from the a...
CVE-2024-4287
- EPSS 0.21%
- Veröffentlicht 20.05.2024 13:15:23
- Zuletzt bearbeitet 10.07.2025 17:19:03
In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application fails to validate or format JSON data sent in an HTTP POST request to `/api/workspace/:workspace-slu...
CVE-2024-4284
- EPSS 0.14%
- Veröffentlicht 19.05.2024 23:15:06
- Zuletzt bearbeitet 10.07.2025 16:14:58
A vulnerability in mintplex-labs/anything-llm allows for a denial of service (DoS) condition through the modification of a user's `id` attribute to a value of 0. This issue affects the current version of the software, with the latest commit id `57984...