XSS Vulnerability in anything-llm Affects Both Desktop and Web Applications
CVE-2024-3166
9.6CRITICAL
What is CVE-2024-3166?
A Cross-Site Scripting (XSS) vulnerability exists within the Mintplex Labs Anything LLM applications, specifically targeting the desktop version 1.2.0 and the latest web version. This vulnerability allows attackers to exploit the application’s capability to fetch and embed content from external websites, leading to arbitrary execution of JavaScript code. In the case of the desktop application, the risk escalates to Remote Code Execution (RCE) due to insecure configurations, prominently the enabling of 'nodeIntegration' alongside the disabling of 'contextIsolation' in Electron's webPreferences. This critical flaw has been remedied in version 1.4.2 of the desktop application.
Affected Version(s)
mintplex-labs/anything-llm < 1.4.2