CVE-2026-24478
- EPSS 0.16%
- Veröffentlicht 26.01.2026 23:23:54
- Zuletzt bearbeitet 28.01.2026 15:52:39
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.10.0, a critical Path Traversal vulnerability in the DrupalWiki integration allows a malicious admin (or an...
CVE-2024-6842
- EPSS 72.56%
- Veröffentlicht 20.03.2025 10:10:27
- Zuletzt bearbeitet 15.10.2025 13:15:50
In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for ...
CVE-2024-10513
- EPSS 0.28%
- Veröffentlicht 20.03.2025 10:09:51
- Zuletzt bearbeitet 14.07.2025 14:01:04
A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with the 'manager' role to access and manipulate the 'anything...
CVE-2024-7771
- EPSS 0.12%
- Veröffentlicht 20.03.2025 10:08:49
- Zuletzt bearbeitet 15.07.2025 15:12:59
A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an audio file with a very low sample rate causes the functionality responsible for transcribing it to cras...
CVE-2024-3279
- EPSS 0.26%
- Veröffentlicht 12.08.2024 13:38:26
- Zuletzt bearbeitet 15.10.2025 13:15:42
An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous attacker, without an account in the application, to import their own databa...
CVE-2024-5216
- EPSS 0.2%
- Veröffentlicht 25.06.2024 11:15:50
- Zuletzt bearbeitet 15.07.2025 15:38:18
A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the application's failure to limit the size of usernames, enabling attackers to...
CVE-2024-5208
- EPSS 0.12%
- Veröffentlicht 19.06.2024 06:15:11
- Zuletzt bearbeitet 15.10.2025 13:15:46
An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows attackers to cause a denial of service (DOS) by shutting down the server through sending invalid upload r...
CVE-2024-5211
- EPSS 0.05%
- Veröffentlicht 12.06.2024 12:15:10
- Zuletzt bearbeitet 15.07.2025 15:04:32
A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the manager to read, delete, or overwrite the 'anyt...
CVE-2024-4287
- EPSS 0.21%
- Veröffentlicht 20.05.2024 13:15:23
- Zuletzt bearbeitet 10.07.2025 17:19:03
In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application fails to validate or format JSON data sent in an HTTP POST request to `/api/workspace/:workspace-slu...
CVE-2024-4284
- EPSS 0.14%
- Veröffentlicht 19.05.2024 23:15:06
- Zuletzt bearbeitet 10.07.2025 16:14:58
A vulnerability in mintplex-labs/anything-llm allows for a denial of service (DoS) condition through the modification of a user's `id` attribute to a value of 0. This issue affects the current version of the software, with the latest commit id `57984...