Prisma Injection Vulnerability in Mintplex Labs' Anything LLM Product
CVE-2024-8251

5.3MEDIUM

Key Information:

Vendor
CVE Published:
20 March 2025

What is CVE-2024-8251?

A vulnerability in Mintplex Labs' Anything LLM before version 1.2.2 exposes an API endpoint that is susceptible to Prisma injection. This flaw permits attackers to manipulate user-provided JSON in requests to the endpoint "/embed/:embedId/stream-chat". By crafting specific JSON objects, such as {"sessionId":{"not":"a"}}, adversaries can exploit the Prisma library's query functionality to access all data associated with user queries, potentially leading to significant data breaches in embedded chat interfaces.

Affected Version(s)

mintplex-labs/anything-llm < 1.2.2

References

CVSS V3.0

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.