Data Exposure Vulnerability in AnythingLLM Using Qdrant by Mintplex Labs
CVE-2026-24477

8.7HIGH

Key Information:

Vendor
CVE Published:
26 January 2026

What is CVE-2026-24477?

A critical vulnerability exists in AnythingLLM where the Qdrant API key can be exposed in plain text to unauthorized users through the /api/setup-complete endpoint. This exposure grants potential attackers full read/write access to the Qdrant vector database, which serves as a foundational component of the application's retrieval and search functionalities. Consequently, this could lead to significant security risks, including compromised semantic search capabilities and the unintended leakage of sensitive documents stored within the Qdrant database. Users are urged to upgrade to AnythingLLM version 1.10.0 or later to mitigate this risk. For further information, refer to the advisory at the provided link.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

anything-llm < 1.10.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.