Prisma Injection Vulnerability in Mintplex Labs' Anything LLM Product
CVE-2024-8251
5.3MEDIUM
What is CVE-2024-8251?
A vulnerability in Mintplex Labs' Anything LLM before version 1.2.2 exposes an API endpoint that is susceptible to Prisma injection. This flaw permits attackers to manipulate user-provided JSON in requests to the endpoint "/embed/:embedId/stream-chat". By crafting specific JSON objects, such as {"sessionId":{"not":"a"}}, adversaries can exploit the Prisma library's query functionality to access all data associated with user queries, potentially leading to significant data breaches in embedded chat interfaces.
Affected Version(s)
mintplex-labs/anything-llm < 1.2.2
References
CVSS V3.0
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
