Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Anythingllm HIGH 8.8
CVE-2026-48116

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the file…

Fix: 1.13.0+
Fix from $1,950 2026-05-28
Anythingllm MEDIUM 5.4
CVE-2026-41318

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, …

Fix: 1.12.1+
Fix from $1,600 2026-04-24
Anythingllm HIGH 7.2
CVE-2026-5627

A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `AgentFlows` component. The vulner…

Fix: after 1.9.1
Fix from $1,950 2026-04-07
Anythingllm MEDIUM 6.4
CVE-2026-32719

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, Th…

Fix: after 1.11.1
Fix from $1,600 2026-03-16
Anythingllm CRITICAL 9.6
CVE-2026-32626

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, An…

Fix: after 1.11.1
Fix from $2,300 2026-03-16
Anythingllm HIGH 8.8
CVE-2026-32628

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a …

Fix: after 1.11.1
Fix from $1,950 2026-03-16
Anythingllm HIGH 7.5
CVE-2026-32617

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, On…

Fix: after 1.11.1
Fix from $1,950 2026-03-16
Anythingllm HIGH 7.5
CVE-2026-24477

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. If AnythingLLM prior to v…

Fix: 1.10.0+
Fix from $1,950 2026-01-27
Anythingllm HIGH 7.2
CVE-2026-24478

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.10.0, …

Fix: 1.10.0+
Fix from $1,950 2026-01-27
Anythingllm MEDIUM 5.3
CVE-2026-21484

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56…

Fix: 1.10.0+
Fix from $1,600 2026-01-03
Anythingllm MEDIUM 5.3
CVE-2025-63390

An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authe…

Mitigation only
Fix from $1,600 2025-12-18
Anythingllm Desktop CRITICAL 9.8
CVE-2024-8196

In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by defaul…

Fix: 1.6.5+
Fix from $2,300 2025-03-20
Anythingllm HIGH 7.5
CVE-2024-8249

mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the API for the embeddable chat f…

Fix: 1.2.2+
Fix from $1,950 2025-03-20
Anythingllm HIGH 7.2
CVE-2024-8248

A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file …

Fix: 1.2.2+
Fix from $1,950 2025-03-20
Anythingllm MEDIUM 5.3
CVE-2024-8251

A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint "/embed/:embed…

Fix: 1.2.2+
Fix from $1,600 2025-03-20
Anythingllm MEDIUM 6.5
CVE-2024-7771

A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an au…

Fix: 1.3.1+
Fix from $1,600 2025-03-20
Anythingllm HIGH 7.5
CVE-2024-6842EPSS 31%

In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The…

Patch available
Fix from $1,950 2025-03-20
Anythingllm HIGH 7.2
CVE-2024-10513

A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to …

Fix: 1.2.2+
Fix from $1,950 2025-03-20
Anythingllm HIGH 8.3
CVE-2024-10109

A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "…

Fix: 1.3.1+
Fix from $1,950 2025-03-20
Anythingllm HIGH 7.2
CVE-2024-13059EPSS 21%

A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the…

Fix: 1.3.1+
Fix from $1,950 2025-02-10
Anythingllm HIGH 7.5
CVE-2024-7783

mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within …

Fix: 1.2.1+
Fix from $1,950 2024-10-29
Anythingllm CRITICAL 9.1
CVE-2024-3279

An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerab…

Fix: 1.0.0+
Fix from $2,300 2024-08-12
Anythingllm HIGH 7.5
CVE-2024-5216

A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, …

Fix: 1.0.0+
Fix from $1,950 2024-06-25
Anythingllm MEDIUM 6.5
CVE-2024-5213

In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the respon…

Fix: after 1.5.3
Fix from $1,600 2024-06-20
Anythingllm MEDIUM 6.5
CVE-2024-5208

An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows atta…

Fix: 1.0.0+
Fix from $1,600 2024-06-19
Anythingllm HIGH 7.2
CVE-2024-5211

A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against p…

Fix: 1.0.0+
Fix from $1,950 2024-06-12
Anythingllm Desktop CRITICAL 9.6
CVE-2024-3166

A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest …

Fix: 1.4.2+
Fix from $2,300 2024-06-06
Anythingllm HIGH 8.8
CVE-2024-3149

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users …

Fix: 1.0.0+
Fix from $1,950 2024-06-06
Anythingllm HIGH 8.8
CVE-2024-3150

In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their …

Fix: 1.0.0+
Fix from $1,950 2024-06-06
Anythingllm MEDIUM 6.5
CVE-2024-3153

mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of serv…

Fix: 1.0.0+
Fix from $1,600 2024-06-06