XSS Vulnerability in anything-llm Affects Both Desktop and Web Applications
CVE-2024-3166

9.6CRITICAL

Key Information:

Vendor
CVE Published:
6 June 2024

What is CVE-2024-3166?

A Cross-Site Scripting (XSS) vulnerability exists within the Mintplex Labs Anything LLM applications, specifically targeting the desktop version 1.2.0 and the latest web version. This vulnerability allows attackers to exploit the application’s capability to fetch and embed content from external websites, leading to arbitrary execution of JavaScript code. In the case of the desktop application, the risk escalates to Remote Code Execution (RCE) due to insecure configurations, prominently the enabling of 'nodeIntegration' alongside the disabling of 'contextIsolation' in Electron's webPreferences. This critical flaw has been remedied in version 1.4.2 of the desktop application.

Affected Version(s)

mintplex-labs/anything-llm < 1.4.2

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.