API Vulnerability in Mintplex Labs' Anything-LLM Product
CVE-2024-10109
8.3HIGH
What is CVE-2024-10109?
A vulnerability in the Mintplex Labs' Anything-LLM repository allows low privilege users to access the sensitive API endpoint '/api/system/custom-models'. This unauthorized access can lead to the alteration of the model's API key and base path, which poses risks such as API key leakage and potential denial of service consequences for chat functionalities.
Affected Version(s)
mintplex-labs/anything-llm < 1.3.1