Mintplexlabs

Anything-llm

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.16%
  • Veröffentlicht 26.01.2026 23:23:54
  • Zuletzt bearbeitet 28.01.2026 15:52:39

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.10.0, a critical Path Traversal vulnerability in the DrupalWiki integration allows a malicious admin (or an...

Exploit
  • EPSS 72.56%
  • Veröffentlicht 20.03.2025 10:10:27
  • Zuletzt bearbeitet 15.10.2025 13:15:50

In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for ...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 20.03.2025 10:09:51
  • Zuletzt bearbeitet 14.07.2025 14:01:04

A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with the 'manager' role to access and manipulate the 'anything...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 20.03.2025 10:08:49
  • Zuletzt bearbeitet 15.07.2025 15:12:59

A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an audio file with a very low sample rate causes the functionality responsible for transcribing it to cras...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 12.08.2024 13:38:26
  • Zuletzt bearbeitet 15.10.2025 13:15:42

An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous attacker, without an account in the application, to import their own databa...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 25.06.2024 11:15:50
  • Zuletzt bearbeitet 15.07.2025 15:38:18

A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the application's failure to limit the size of usernames, enabling attackers to...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 19.06.2024 06:15:11
  • Zuletzt bearbeitet 15.10.2025 13:15:46

An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows attackers to cause a denial of service (DOS) by shutting down the server through sending invalid upload r...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 12.06.2024 12:15:10
  • Zuletzt bearbeitet 15.07.2025 15:04:32

A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the manager to read, delete, or overwrite the 'anyt...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 20.05.2024 13:15:23
  • Zuletzt bearbeitet 10.07.2025 17:19:03

In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application fails to validate or format JSON data sent in an HTTP POST request to `/api/workspace/:workspace-slu...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 19.05.2024 23:15:06
  • Zuletzt bearbeitet 10.07.2025 16:14:58

A vulnerability in mintplex-labs/anything-llm allows for a denial of service (DoS) condition through the modification of a user's `id` attribute to a value of 0. This issue affects the current version of the software, with the latest commit id `57984...