Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Anythingllm HIGH 8.7
CVE-2024-3110

A stored Cross-Site Scripting (XSS) vulnerability exists in the mintplex-labs/anything-llm application, affecting versions up to and including the la…

Fix: 1.0.0+
Fix from $1,950 2024-06-06
Anythingllm MEDIUM 5.3
CVE-2024-3102

A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login pr…

Fix: 1.0.0+
Fix from $1,600 2024-06-06
Anythingllm CRITICAL 9.8
CVE-2024-3104

A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment variables. Attackers can exploit t…

Fix: 1.0.0+
Fix from $2,300 2024-06-06
Anythingllm CRITICAL 9.4
CVE-2024-3033

An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-…

Fix: 1.0.0+
Fix from $2,300 2024-06-06
Anythingllm HIGH 8.8
CVE-2024-3152

mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit t…

Fix: 1.0.0+
Fix from $1,950 2024-06-06
Anythingllm HIGH 7.5
CVE-2024-4084

A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of mintplex-labs/anything-llm, allowing attackers to bypass the offic…

Fix: after 1.5.4
Fix from $1,950 2024-06-05
Anythingllm HIGH 7.2
CVE-2024-4287

In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application…

Fix: 1.0.0+
Fix from $1,950 2024-05-20
Anythingllm MEDIUM 6.5
CVE-2024-2913

A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers…

Fix: after 1.0.0
Fix from $1,600 2024-05-07
Anythingllm HIGH 8.0
CVE-2024-3029

In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to the '/system/enable-multi-use…

Fix: 1.0.0+
Fix from $1,950 2024-04-16
Anythingllm HIGH 7.2
CVE-2024-3028

mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipu…

Fix: 1.0.0+
Fix from $1,950 2024-04-16
Anythingllm CRITICAL 9.1
CVE-2024-0404

A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository, allowing unauthorized creati…

Fix: 1.0.0+
Fix from $2,300 2024-04-16
Anythingllm HIGH 8.1
CVE-2024-0549

mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete f…

Fix: 1.0.0+
Fix from $1,950 2024-04-16
Anythingllm HIGH 7.5
CVE-2024-3569

A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is running in 'just me' mode with a …

Fix: 1.0.0+
Fix from $1,950 2024-04-10
Anythingllm MEDIUM 5.4
CVE-2024-3570

A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm repository, allowing attackers t…

Fix: 1.0.0+
Fix from $1,600 2024-04-10
Anythingllm HIGH 7.2
CVE-2024-3101

In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by deactivating 'Multi-User Mode'. …

Fix: 1.0.0+
Fix from $1,950 2024-04-10
Anythingllm HIGH 7.2
CVE-2024-3283

A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin roles through a mass assignment i…

Fix: 1.0.0+
Fix from $1,950 2024-04-10
Anythingllm CRITICAL 9.9
CVE-2024-3025

mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input in the logo filename functio…

Fix: 1.0.0+
Fix from $2,300 2024-04-10
Anythingllm MEDIUM 6.5
CVE-2024-0765

As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip and r…

Fix: 1.0.0+
Fix from $1,600 2024-03-03
Anythingllm HIGH 7.2
CVE-2024-0795

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from…

Fix: 1.0.0+
Fix from $1,950 2024-03-02
Anythingllm MEDIUM 6.5
CVE-2024-0550

A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the P…

Fix: 1.0.0+
Fix from $1,600 2024-02-28
Anythingllm HIGH 8.1
CVE-2024-0763

Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would …

Fix: 1.0.0+
Fix from $1,950 2024-02-27
Anythingllm HIGH 7.1
CVE-2024-0551

Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been gran…

Fix: 1.0.0+
Fix from $1,950 2024-02-27
Anythingllm HIGH 7.5
CVE-2024-0759

Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission level of manager or admin, the…

Fix: 1.0.0+
Fix from $1,950 2024-02-27
Anythingllm MEDIUM 6.5
CVE-2024-0798

A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'…

Patch available
Fix from $1,600 2024-02-26
Anythingllm HIGH 8.8
CVE-2024-0439

As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most manager…

Fix: 1.0.0+
Fix from $1,950 2024-02-26
Anythingllm HIGH 7.5
CVE-2024-0455

The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) co…

Patch available
Fix from $1,950 2024-02-26
Anythingllm MEDIUM 6.5
CVE-2024-0440

Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host fi…

Patch available
Fix from $1,600 2024-02-26
Anythingllm MEDIUM 5.9
CVE-2024-0436

Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing …

Fix: 1.0.0+
Fix from $1,600 2024-02-26
Anythingllm MEDIUM 5.4
CVE-2024-0435

User can send a chat that contains an XSS opportunity that will then run when the chat is sent and on subsequent page loads. Given the minimum requi…

Patch available
Fix from $1,600 2024-02-26
Anythingllm HIGH 7.5
CVE-2024-22422

AnythingLLM is an application that turns any document, resource, or piece of content into context that any LLM can use as references during chatting.…

Fix: 2024-01-18+
Fix from $1,950 2024-01-19