Mintplexlabs
Mintplexlabs Anythingllm: vulnerabilidades y CVE
Mintplexlabs Anythingllm tiene 71 vulnerabilidades publicadas, 20 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE71
Últimos 12 meses20
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-88055 | Media (5.5) | 0.28% | — | 10 sept 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the manager role can store meta_page_title or meta_page_favicon through… |
| CVE-2026-72917 | Media (5.9) | 0.35% | — | 10 ago 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in… |
| CVE-2026-55611 | Ninguna (0) | 0.40% | — | 24 jun 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.11.1 until 1.14.1, userId/workspaceId scoping to the parsed-files read/delete paths was… |
| CVE-2026-48789 | Media (4.3) | 0.34% | — | 24 jun 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, the document folder listing route can accept an encoded absolute… |
| CVE-2026-48116 | Alta (8.8) | 0.54% | — | 28 may 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill passes its LLM-controlled pattern… |
| CVE-2026-47713 | Media (4.3) | 0.30% | — | 28 may 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, an approved mobile device token created in single-user mode can survive… |
| CVE-2026-45403 | Baja (2.5) | 0.23% | — | 28 may 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only the top-level source… |
| CVE-2026-42456 | Media (4.3) | 0.34% | — | 8 may 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, GET /api/workspace/:slug/tts/:chatId in AnythingLLM returns the… |
| CVE-2026-41318 | Media (5.4) | 0.27% | — | 24 abr 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, AnythingLLM's in-chat markdown renderer has an unsafe custom rule for… |
| CVE-2026-5627 | Alta (7.2) | 1.1% | — | 7 abr 2026 | A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `AgentFlows` component. The vulnerability arises from improper handling of user input in the `loadFlow`… |
| CVE-2026-32719 | Media (6.4) | 0.52% | — | 16 mar 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The ImportedPlugin.importCommunityItemFromUrl() function in… |
| CVE-2026-32717 | Baja (2.7) | 0.33% | — | 16 mar 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, in multi-user mode, AnythingLLM blocks suspended users on the normal… |
| CVE-2026-32715 | Baja (3.8) | 0.27% | — | 16 mar 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-preferences endpoints allow manager role access,… |
| CVE-2026-32628 | Alta (7.7) | 0.45% | — | 16 mar 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL injection vulnerability in the built-in SQL Agent plugin allows… |
| CVE-2026-32626 | Crítica (9.6) | 0.73% | — | 16 mar 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the… |
| CVE-2026-32617 | Alta (7.5) | 0.40% | — | 16 mar 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, On default installations where no password or API key has been… |
| CVE-2026-24478 | Alta (7.2) | 0.95% | — | 27 ene 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.10.0, a critical Path Traversal vulnerability in the DrupalWiki integration… |
| CVE-2026-24477 | Alta (8.7) | 1.7% | — | 27 ene 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. If AnythingLLM prior to version 1.10.0 is configured to use Qdrant as the vector database with… |
| CVE-2026-21484 | Media (5.3) | 0.77% | — | 3 ene 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery endpoint… |
| CVE-2025-63390 | Media (5.3) | 0.55% | — | 18 dic 2025 | An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote attackers to… |
| CVE-2024-8251 | Media (5.3) | 0.48% | — | 20 mar 2025 | A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint "/embed/:embedId/stream-chat" where user-provided JSON is directly taken to the… |
| CVE-2024-8249 | Alta (7.5) | 0.68% | — | 20 mar 2025 | mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the API for the embeddable chat functionality. An attacker can exploit this vulnerability by sending a… |
| CVE-2024-8248 | Alta (7.2) | 0.88% | — | 20 mar 2025 | A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file read and write in the storage directory. This can result in privilege… |
| CVE-2024-7771 | Media (6.5) | 0.76% | — | 20 mar 2025 | A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an audio file with a very low sample rate causes the functionality… |
| CVE-2024-6842 | Alta (7.5) | 31% | — | 20 mar 2025 | In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive… |
| CVE-2024-10513 | Alta (7.2) | 0.88% | — | 20 mar 2025 | A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with the 'manager' role to… |
| CVE-2024-10109 | Alta (8.3) | 0.52% | — | 20 mar 2025 | A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the… |
| CVE-2024-13059 | Alta (7.2) | 21% | — | 10 feb 2025 | A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library. This vulnerability can lead to arbitrary file write,… |
| CVE-2024-7783 | Alta (7.5) | 0.34% | — | 29 oct 2024 | mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode.… |
| CVE-2024-3279 | Crítica (9.1) | 0.65% | — | 12 ago 2024 | An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous attacker, without an account in the… |