Mintplex-Labs' Anything-LLM Vulnerable to Improper Input Validation
CVE-2024-3028
7.2HIGH
What is CVE-2024-3028?
The Anything-LLM product from Mintplex Labs is vulnerable to improper input validation, which permits attackers to access and delete arbitrary files on the server. By exploiting the 'logo_filename' parameter within the 'system-preferences' API endpoint, attackers can craft requests to read sensitive files, such as the application's .env file. Additionally, by manipulating the same parameter, attackers can invoke the 'remove-logo' API endpoint to delete files from the server. This vulnerability stems from inadequate sanitization of user-supplied input, posing significant security risks to affected installations.
Affected Version(s)
mintplex-labs/anything-llm < 1.0.0