CVE-2024-10109
- EPSS 0.49%
- Veröffentlicht 20.03.2025 10:09:27
- Zuletzt bearbeitet 11.07.2025 20:43:39
A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the model's API key and base path, lea...
CVE-2024-7771
- EPSS 0.7%
- Veröffentlicht 20.03.2025 10:08:49
- Zuletzt bearbeitet 15.07.2025 15:12:59
A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an audio file with a very low sample rate causes the functionality responsible for transcribing it to cras...
CVE-2024-8251
- EPSS 0.45%
- Veröffentlicht 20.03.2025 10:08:48
- Zuletzt bearbeitet 15.10.2025 13:15:54
A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint "/embed/:embedId/stream-chat" where user-provided JSON is directly taken to the Prisma library's where clause. An a...
CVE-2024-13059
- EPSS 19.78%
- Veröffentlicht 10.02.2025 19:15:37
- Zuletzt bearbeitet 09.07.2025 15:11:29
A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library. This vulnerability can lead to arbitrary file write, which can subsequently result i...
CVE-2024-7783
- EPSS 0.34%
- Veröffentlicht 29.10.2024 13:15:10
- Zuletzt bearbeitet 31.10.2024 15:49:02
mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the ...
CVE-2024-3279
- EPSS 0.65%
- Veröffentlicht 12.08.2024 13:38:26
- Zuletzt bearbeitet 15.10.2025 13:15:42
An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous attacker, without an account in the application, to import their own databa...
CVE-2024-5216
- EPSS 0.59%
- Veröffentlicht 25.06.2024 11:15:50
- Zuletzt bearbeitet 15.07.2025 15:38:18
A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the application's failure to limit the size of usernames, enabling attackers to...
CVE-2024-5213
- EPSS 0.46%
- Veröffentlicht 20.06.2024 03:15:09
- Zuletzt bearbeitet 15.10.2025 13:15:46
In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the response after login (`POST /api/request-token`) and after account creations (`POST /api/admin/users/new`)....
CVE-2024-5208
- EPSS 0.62%
- Veröffentlicht 19.06.2024 06:15:11
- Zuletzt bearbeitet 15.10.2025 13:15:46
An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows attackers to cause a denial of service (DOS) by shutting down the server through sending invalid upload r...
CVE-2024-5211
- EPSS 1.05%
- Veröffentlicht 12.06.2024 12:15:10
- Zuletzt bearbeitet 15.07.2025 15:04:32
A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the manager to read, delete, or overwrite the 'anyt...