Prisma Injection Vulnerability in Mintplex Labs' Anything LLM Product
CVE-2024-8251
5.3MEDIUM
What is CVE-2024-8251?
A vulnerability in Mintplex Labs' Anything LLM before version 1.2.2 exposes an API endpoint that is susceptible to Prisma injection. This flaw permits attackers to manipulate user-provided JSON in requests to the endpoint "/embed/:embedId/stream-chat". By crafting specific JSON objects, such as {"sessionId":{"not":"a"}}, adversaries can exploit the Prisma library's query functionality to access all data associated with user queries, potentially leading to significant data breaches in embedded chat interfaces.
Affected Version(s)
mintplex-labs/anything-llm < 1.2.2