Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-48116 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the file… Anythingllm 1.13.0+ Fix from $1,9502026-05-28 MEDIUM 5.4 CVE-2026-41318 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, … Anythingllm 1.12.1+ Fix from $1,6002026-04-24 HIGH 7.2 CVE-2026-5627 A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `AgentFlows` component. The vulner… Anythingllm after 1.9.1 Fix from $1,9502026-04-07 MEDIUM 6.4 CVE-2026-32719 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, Th… Anythingllm after 1.11.1 Fix from $1,6002026-03-16 CRITICAL 9.6 CVE-2026-32626 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, An… Anythingllm after 1.11.1 Fix from $2,3002026-03-16 HIGH 8.8 CVE-2026-32628 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a … Anythingllm after 1.11.1 Fix from $1,9502026-03-16 HIGH 7.5 CVE-2026-32617 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, On… Anythingllm after 1.11.1 Fix from $1,9502026-03-16 HIGH 7.5 CVE-2026-24477 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. If AnythingLLM prior to v… Anythingllm 1.10.0+ Fix from $1,9502026-01-27 HIGH 7.2 CVE-2026-24478 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.10.0, … Anythingllm 1.10.0+ Fix from $1,9502026-01-27 MEDIUM 5.3 CVE-2026-21484 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56… Anythingllm 1.10.0+ Fix from $1,6002026-01-03 MEDIUM 5.3 CVE-2025-63390 An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authe… Anythingllm Mitigation only Fix from $1,6002025-12-18 CRITICAL 9.8 CVE-2024-8196 In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by defaul… Anythingllm Desktop 1.6.5+ Fix from $2,3002025-03-20 HIGH 7.5 CVE-2024-8249 mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the API for the embeddable chat f… Anythingllm 1.2.2+ Fix from $1,9502025-03-20 HIGH 7.2 CVE-2024-8248 A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file … Anythingllm 1.2.2+ Fix from $1,9502025-03-20 MEDIUM 5.3 CVE-2024-8251 A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint "/embed/:embed… Anythingllm 1.2.2+ Fix from $1,6002025-03-20 MEDIUM 6.5 CVE-2024-7771 A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an au… Anythingllm 1.3.1+ Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-6842EPSS 31% In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The… Anythingllm Patch available Fix from $1,9502025-03-20 HIGH 7.2 CVE-2024-10513 A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to … Anythingllm 1.2.2+ Fix from $1,9502025-03-20 HIGH 8.3 CVE-2024-10109 A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "… Anythingllm 1.3.1+ Fix from $1,9502025-03-20 HIGH 7.2 CVE-2024-13059EPSS 21% A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the… Anythingllm 1.3.1+ Fix from $1,9502025-02-10 HIGH 7.5 CVE-2024-7783 mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within … Anythingllm 1.2.1+ Fix from $1,9502024-10-29 CRITICAL 9.1 CVE-2024-3279 An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerab… Anythingllm 1.0.0+ Fix from $2,3002024-08-12 HIGH 7.5 CVE-2024-5216 A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, … Anythingllm 1.0.0+ Fix from $1,9502024-06-25 MEDIUM 6.5 CVE-2024-5213 In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the respon… Anythingllm after 1.5.3 Fix from $1,6002024-06-20 MEDIUM 6.5 CVE-2024-5208 An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows atta… Anythingllm 1.0.0+ Fix from $1,6002024-06-19 HIGH 7.2 CVE-2024-5211 A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against p… Anythingllm 1.0.0+ Fix from $1,9502024-06-12 CRITICAL 9.6 CVE-2024-3166 A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest … Anythingllm Desktop 1.4.2+ Fix from $2,3002024-06-06 HIGH 8.8 CVE-2024-3149 A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users … Anythingllm 1.0.0+ Fix from $1,9502024-06-06 HIGH 8.8 CVE-2024-3150 In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their … Anythingllm 1.0.0+ Fix from $1,9502024-06-06 MEDIUM 6.5 CVE-2024-3153 mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of serv… Anythingllm 1.0.0+ Fix from $1,6002024-06-06