CVE-2024-3104
- EPSS 6.58%
- Veröffentlicht 06.06.2024 18:15:17
- Zuletzt bearbeitet 21.11.2024 09:28:54
A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment variables. Attackers can exploit this vulnerability by injecting arbitrary environment variables via the `POST /api/system/update-env` ...
CVE-2024-3152
- EPSS 0.13%
- Veröffentlicht 06.06.2024 18:15:17
- Zuletzt bearbeitet 15.10.2025 13:15:42
mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit these vulnerabilities to escalate privileges from a default user role to an admin role, read and delet...
CVE-2024-3033
- EPSS 0.15%
- Veröffentlicht 06.06.2024 18:15:17
- Zuletzt bearbeitet 21.11.2024 09:28:43
An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the VectorDB, includ...
CVE-2024-4084
- EPSS 0.06%
- Veröffentlicht 05.06.2024 00:15:09
- Zuletzt bearbeitet 21.11.2024 09:42:09
A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of mintplex-labs/anything-llm, allowing attackers to bypass the official fix intended to restrict access to intranet IP addresses and protocols. Despite efforts to filter...
CVE-2024-4286
- EPSS 0.1%
- Veröffentlicht 26.05.2024 23:15:21
- Zuletzt bearbeitet 15.04.2026 00:35:42
Mintplex-Labs' anything-llm application is vulnerable to improper neutralization of special elements used in an expression language statement, identified in the commit id `57984fa85c31988b2eff429adfc654c46e0c342a`. The vulnerability arises from the a...
CVE-2024-4287
- EPSS 0.22%
- Veröffentlicht 20.05.2024 13:15:23
- Zuletzt bearbeitet 10.07.2025 17:19:03
In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application fails to validate or format JSON data sent in an HTTP POST request to `/api/workspace/:workspace-slu...
CVE-2024-4284
- EPSS 0.14%
- Veröffentlicht 19.05.2024 23:15:06
- Zuletzt bearbeitet 10.07.2025 16:14:58
A vulnerability in mintplex-labs/anything-llm allows for a denial of service (DoS) condition through the modification of a user's `id` attribute to a value of 0. This issue affects the current version of the software, with the latest commit id `57984...
CVE-2024-2913
- EPSS 0.11%
- Veröffentlicht 07.05.2024 00:15:08
- Zuletzt bearbeitet 09.07.2025 19:32:48
A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerability by sending multiple concurrent requests to accept a single user invit...
- EPSS 0.21%
- Veröffentlicht 16.04.2024 00:15:11
- Zuletzt bearbeitet 09.07.2025 19:34:23
In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to the '/system/enable-multi-user' endpoint. This triggers an error that is caught by a catch block, which in turn deletes all users ...
CVE-2024-3028
- EPSS 0.19%
- Veröffentlicht 16.04.2024 00:15:11
- Zuletzt bearbeitet 09.07.2025 19:34:59
mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipulating the 'logo_filename' parameter in the 'system-preferences' API endpoint, an attacker can constr...