API Vulnerability in Mintplex Labs' Anything-LLM Product
CVE-2024-10109

8.3HIGH

Key Information:

Vendor
CVE Published:
20 March 2025

What is CVE-2024-10109?

A vulnerability in the Mintplex Labs' Anything-LLM repository allows low privilege users to access the sensitive API endpoint '/api/system/custom-models'. This unauthorized access can lead to the alteration of the model's API key and base path, which poses risks such as API key leakage and potential denial of service consequences for chat functionalities.

Affected Version(s)

mintplex-labs/anything-llm < 1.3.1

References

CVSS V3.0

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.