Data Exposure Vulnerability in AnythingLLM Using Qdrant by Mintplex Labs
CVE-2026-24477
What is CVE-2026-24477?
A critical vulnerability exists in AnythingLLM where the Qdrant API key can be exposed in plain text to unauthorized users through the /api/setup-complete endpoint. This exposure grants potential attackers full read/write access to the Qdrant vector database, which serves as a foundational component of the application's retrieval and search functionalities. Consequently, this could lead to significant security risks, including compromised semantic search capabilities and the unintended leakage of sensitive documents stored within the Qdrant database. Users are urged to upgrade to AnythingLLM version 1.10.0 or later to mitigate this risk. For further information, refer to the advisory at the provided link.
Affected Version(s)
anything-llm < 1.10.0
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
