CVE-2026-32719
- EPSS 0.04%
- Veröffentlicht 13.03.2026 21:25:31
- Zuletzt bearbeitet 16.03.2026 20:29:53
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The ImportedPlugin.importCommunityItemFromUrl() function in server/utils/agents/imported.js downloads a...
CVE-2026-32717
- EPSS 0.03%
- Veröffentlicht 13.03.2026 21:23:48
- Zuletzt bearbeitet 16.03.2026 20:31:45
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, in multi-user mode, AnythingLLM blocks suspended users on the normal JWT-backed session path, but it do...
CVE-2026-32715
- EPSS 0.03%
- Veröffentlicht 13.03.2026 21:22:00
- Zuletzt bearbeitet 16.03.2026 20:00:30
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-preferences endpoints allow manager role access, while every other surface that ...
CVE-2026-32628
- EPSS 0.03%
- Veröffentlicht 13.03.2026 20:50:15
- Zuletzt bearbeitet 16.03.2026 20:33:27
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL injection vulnerability in the built-in SQL Agent plugin allows any user who can invoke the agent...
CVE-2026-32626
- EPSS 0.05%
- Veröffentlicht 13.03.2026 20:14:30
- Zuletzt bearbeitet 16.03.2026 20:34:47
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the chat rendering pipeline that es...
CVE-2026-24478
- EPSS 0.23%
- Veröffentlicht 26.01.2026 23:23:54
- Zuletzt bearbeitet 28.01.2026 15:52:39
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.10.0, a critical Path Traversal vulnerability in the DrupalWiki integration allows a malicious admin (or an...
CVE-2024-6842
- EPSS 77.32%
- Veröffentlicht 20.03.2025 10:10:27
- Zuletzt bearbeitet 15.10.2025 13:15:50
In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for ...
CVE-2024-10513
- EPSS 0.28%
- Veröffentlicht 20.03.2025 10:09:51
- Zuletzt bearbeitet 14.07.2025 14:01:04
A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with the 'manager' role to access and manipulate the 'anything...
CVE-2024-7771
- EPSS 0.12%
- Veröffentlicht 20.03.2025 10:08:49
- Zuletzt bearbeitet 15.07.2025 15:12:59
A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an audio file with a very low sample rate causes the functionality responsible for transcribing it to cras...
CVE-2024-3279
- EPSS 0.26%
- Veröffentlicht 12.08.2024 13:38:26
- Zuletzt bearbeitet 15.10.2025 13:15:42
An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous attacker, without an account in the application, to import their own databa...