API Vulnerability in Mintplex Labs' Anything-LLM Product
CVE-2024-10109
8.3HIGH
What is CVE-2024-10109?
A vulnerability in the Mintplex Labs' Anything-LLM repository allows low privilege users to access the sensitive API endpoint '/api/system/custom-models'. This unauthorized access can lead to the alteration of the model's API key and base path, which poses risks such as API key leakage and potential denial of service consequences for chat functionalities.
Affected Version(s)
mintplex-labs/anything-llm < 1.3.1
References
CVSS V3.0
Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
