Skip to main content

Vendor archive

mintplexlabs CVEs

Beta · best-effort

73 CVEs tagged to vendor mintplexlabs10 Critical, 37 High, 22 Medium, 4 Low, 0 Unrated.

CVE-2024-13059

Published Feb 10, 2025

A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library. This vulnerab…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7783

Published Oct 29, 2024

mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3279

Published Aug 12, 2024

An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous atta…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5216

Published Jun 25, 2024

A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the appl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5213

Published Jun 20, 2024

In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the response after login (`POST /api/req…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5208

Published Jun 19, 2024

An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows attackers to cause a denial of ser…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5211

Published Jun 12, 2024

A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vu…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3153

Published Jun 6, 2024

mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifica…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3150

Published Jun 6, 2024

In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their privileges to Administrator. T…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3149

Published Jun 6, 2024

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users with manager or admin roles, p…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3110

Published Jun 6, 2024

A stored Cross-Site Scripting (XSS) vulnerability exists in the mintplex-labs/anything-llm application, affecting versions up to and including the latest before 1.0.0. The vulnera…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3102

Published Jun 6, 2024

A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-tok…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3152

Published Jun 6, 2024

mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit these vulnerabilities to escala…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3104

Published Jun 6, 2024

A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment variables. Attackers can exploit this vulnerability by injecting…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-3033

Published Jun 6, 2024

An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unaut…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-4084

Published Jun 5, 2024

A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of mintplex-labs/anything-llm, allowing attackers to bypass the official fix intended to restrict a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4287

Published May 20, 2024

In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application fails to validate or format J…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4284

Published May 19, 2024

A vulnerability in mintplex-labs/anything-llm allows for a denial of service (DoS) condition through the modification of a user's `id` attribute to a value of 0. This issue affect…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2913

Published May 7, 2024

A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerabilit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3029

Published Apr 16, 2024

In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to the '/system/enable-multi-user' endpoint. This triggers an…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3028

Published Apr 16, 2024

mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipulating the 'logo_filename' par…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0549

Published Apr 16, 2024

mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete files and folders within the fi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0404

Published Apr 16, 2024

A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository, allowing unauthorized creation of high-privileged accounts…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-3570

Published Apr 10, 2024

A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm repository, allowing attackers to execute arbitrary JavaScript…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 73 CVEsPage 2 of 3