Data Exposure Vulnerability in AnythingLLM Using Qdrant by Mintplex Labs
CVE-2026-24477
What is CVE-2026-24477?
A critical vulnerability exists in AnythingLLM where the Qdrant API key can be exposed in plain text to unauthorized users through the /api/setup-complete endpoint. This exposure grants potential attackers full read/write access to the Qdrant vector database, which serves as a foundational component of the application's retrieval and search functionalities. Consequently, this could lead to significant security risks, including compromised semantic search capabilities and the unintended leakage of sensitive documents stored within the Qdrant database. Users are urged to upgrade to AnythingLLM version 1.10.0 or later to mitigate this risk. For further information, refer to the advisory at the provided link.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
anything-llm < 1.10.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
