Mintplex-Labs' Anything-LLM Vulnerable to Improper Input Validation
CVE-2024-3028

7.2HIGH

Key Information:

Vendor
CVE Published:
16 April 2024

What is CVE-2024-3028?

The Anything-LLM product from Mintplex Labs is vulnerable to improper input validation, which permits attackers to access and delete arbitrary files on the server. By exploiting the 'logo_filename' parameter within the 'system-preferences' API endpoint, attackers can craft requests to read sensitive files, such as the application's .env file. Additionally, by manipulating the same parameter, attackers can invoke the 'remove-logo' API endpoint to delete files from the server. This vulnerability stems from inadequate sanitization of user-supplied input, posing significant security risks to affected installations.

Affected Version(s)

mintplex-labs/anything-llm < 1.0.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.