XSS Vulnerability in anything-llm Affects Both Desktop and Web Applications
CVE-2024-3166
What is CVE-2024-3166?
A Cross-Site Scripting (XSS) vulnerability exists within the Mintplex Labs Anything LLM applications, specifically targeting the desktop version 1.2.0 and the latest web version. This vulnerability allows attackers to exploit the application’s capability to fetch and embed content from external websites, leading to arbitrary execution of JavaScript code. In the case of the desktop application, the risk escalates to Remote Code Execution (RCE) due to insecure configurations, prominently the enabling of 'nodeIntegration' alongside the disabling of 'contextIsolation' in Electron's webPreferences. This critical flaw has been remedied in version 1.4.2 of the desktop application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mintplex-labs/anything-llm < 1.4.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
