Mintplexlabs

Anythingllm

68 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.66%
  • Veröffentlicht 06.06.2024 19:16:00
  • Zuletzt bearbeitet 21.11.2024 09:29:00

mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifically, the server can be shut down by sending an invalid upload request. ...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 06.06.2024 19:16:00
  • Zuletzt bearbeitet 21.11.2024 09:29:00

In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their privileges to Administrator. The issue arises from improper input validation when handling HTTP POST ...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 06.06.2024 19:16:00
  • Zuletzt bearbeitet 21.11.2024 09:29:00

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users with manager or admin roles, processes uploaded links through an internal Collector API using a headl...

Exploit
  • EPSS 0.67%
  • Veröffentlicht 06.06.2024 19:15:59
  • Zuletzt bearbeitet 21.11.2024 09:28:55

A stored Cross-Site Scripting (XSS) vulnerability exists in the mintplex-labs/anything-llm application, affecting versions up to and including the latest before 1.0.0. The vulnerability arises from the application's failure to properly sanitize and v...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 06.06.2024 19:15:59
  • Zuletzt bearbeitet 21.11.2024 09:28:54

A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-token` endpoint. The vulnerability arises from improper handling of values...

Exploit
  • EPSS 0.57%
  • Veröffentlicht 06.06.2024 18:15:17
  • Zuletzt bearbeitet 15.10.2025 13:15:42

mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit these vulnerabilities to escalate privileges from a default user role to an admin role, read and delet...

Exploit
  • EPSS 0.97%
  • Veröffentlicht 06.06.2024 18:15:17
  • Zuletzt bearbeitet 21.11.2024 09:28:54

A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment variables. Attackers can exploit this vulnerability by injecting arbitrary environment variables via the `POST /api/system/update-env` ...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 06.06.2024 18:15:17
  • Zuletzt bearbeitet 21.11.2024 09:28:43

An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the VectorDB, includ...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 05.06.2024 00:15:09
  • Zuletzt bearbeitet 21.11.2024 09:42:09

A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of mintplex-labs/anything-llm, allowing attackers to bypass the official fix intended to restrict access to intranet IP addresses and protocols. Despite efforts to filter...

  • EPSS 0.36%
  • Veröffentlicht 26.05.2024 23:15:21
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Mintplex-Labs' anything-llm application is vulnerable to improper neutralization of special elements used in an expression language statement, identified in the commit id `57984fa85c31988b2eff429adfc654c46e0c342a`. The vulnerability arises from the a...