Skip to main content

Vendor archive

mintplexlabs CVEs

Beta · best-effort

73 CVEs tagged to vendor mintplexlabs10 Critical, 37 High, 22 Medium, 4 Low, 0 Unrated.

CVE-2024-3569

Published Apr 10, 2024

A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is running in 'just me' mode with a password. An attacker can expl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3283

Published Apr 10, 2024

A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin roles through a mass assignment issue. The '/admin/system-prefe…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3101

Published Apr 10, 2024

In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by deactivating 'Multi-User Mode'. By sending a specially crafted…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3025

Published Apr 10, 2024

mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input in the logo filename functionality. Attackers can exploit…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-0765

Published Mar 3, 2024

As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip and read that export that would ena…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0795

Published Mar 2, 2024

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0550

Published Feb 28, 2024

A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any val…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0763

Published Feb 27, 2024

Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need access to the server at s…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0551

Published Feb 27, 2024

Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been granted access to the system prior…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0759

Published Feb 27, 2024

Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission level of manager or admin, they could link-scrape internally…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0798

Published Feb 26, 2024

A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'. Despite the intended restric…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0455

Published Feb 26, 2024

The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) could put in the URL ``` http://…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0440

Published Feb 26, 2024

Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host files and other relatively store…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0439

Published Feb 26, 2024

As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0436

Published Feb 26, 2024

Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0435

Published Feb 26, 2024

User can send a chat that contains an XSS opportunity that will then run when the chat is sent and on subsequent page loads. Given the minimum requirement for a user to send a ch…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0879

Published Jan 25, 2024

Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22422

Published Jan 19, 2024

AnythingLLM is an application that turns any document, resource, or piece of content into context that any LLM can use as references during chatting. In versions prior to commit `…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 51-73 of 73 CVEsPage 3 of 3