VendorsMintplex Labsanythingllmany version
Vulnerabilities

Mintplex Labs AnythingLLM any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

65CVEs
CVE-2026-24478
AnythingLLM vulnerable to Path Traversal
Published 2026-01-26 · Analyzed
7.2EPSS 0.009
CVE-2024-0795
Create user API role not enforced
Published 2024-03-02 · Analyzed
7.2EPSS 0.009
CVE-2024-10513
Path Traversal in mintplex-labs/anything-llm
Published 2025-03-20 · Analyzed
7.2EPSS 0.009
CVE-2024-8248
Path Traversal in mintplex-labs/anything-llm
Published 2025-03-20 · Analyzed
7.2EPSS 0.009
CVE-2024-3028
Improper Input Validation in mintplex-labs/anything-llm
Published 2024-04-16 · Analyzed
7.2EPSS 0.008
CVE-2024-3101
Privilege Escalation via Improper Input Validation in mintplex-labs/anything-llm
Published 2024-04-10 · Analyzed
7.2EPSS 0.008
CVE-2024-0551
Download and export of file via default user role
Published 2024-02-27 · Analyzed
7.1EPSS 0.006
CVE-2024-0436
Prevent timing attack for single-user password check
Published 2024-02-25 · Modified
7.1EPSS 0.005
CVE-2024-7771
Denial of Service in mintplex-labs/anything-llm
Published 2025-03-20 · Analyzed
6.5EPSS 0.008
CVE-2024-3153
Uncontrolled Resource Consumption in mintplex-labs/anything-llm
Published 2024-06-06 · Modified
6.5EPSS 0.007
CVE-2024-5208
Uncontrolled Resource Consumption in mintplex-labs/anything-llm
Published 2024-06-19 · Modified
6.5EPSS 0.006
CVE-2024-5213
Exposure of Sensitive Information in mintplex-labs/anything-llm
Published 2024-06-20 · Modified
6.5EPSS 0.005
CVE-2024-2913
Race Condition Vulnerability in mintplex-labs/anything-llm
Published 2024-05-06 · Analyzed
6.5EPSS 0.003
CVE-2026-32719
AnythingLLM has a Zip Slip Path Traversal and Code Execution via Community Hub Plugin Import
Published 2026-03-13 · Analyzed
6.4EPSS 0.005
CVE-2024-3570
Stored XSS leading to Admin Account Takeover in mintplex-labs/anything-llm
Published 2024-04-10 · Analyzed
5.4EPSS 0.003
CVE-2026-41318
AnythingLLM vulnerable to stored DOM XSS in chart caption renderer - LLM-driven prompt injection produces executable HTML via unsanitized renderMarkdown(content.caption) in Chartable component
Published 2026-04-24 · Analyzed
5.4EPSS 0.003
CVE-2026-21484
AnythingLLM Vulnerable to Username Enumeration w/ Password Recovery
Published 2026-01-03 · Analyzed
5.3EPSS 0.008
CVE-2024-8251
Prisma Injection in mintplex-labs/anything-llm
Published 2025-03-20 · Modified
5.3EPSS 0.005
CVE-2024-3102
JSON Injection in mintplex-labs/anything-llm
Published 2024-06-06 · Modified
5.3EPSS 0.005
CVE-2024-4284
Denial of Service in mintplex-labs/anything-llm
Published 2024-05-19 · Analyzed
4.9EPSS 0.006
CVE-2026-42456
AnythingLLM: Cross-User TTS Audio Disclosure via Chat ID (IDOR)
Published 2026-05-08 · Analyzed
4.3EPSS 0.003
CVE-2026-47713
AnythingLLM: Legacy mobile device tokens bypass multi-user workspace scoping after mode migration
Published 2026-05-28 · Analyzed
4.3EPSS 0.003
CVE-2026-32715
AnythingLLM Manager Privilege Bypass Allows Access to Admin-Only System Preferences
Published 2026-03-13 · Analyzed
3.8EPSS 0.003
CVE-2026-32717
AnythingLLM access control bypass: suspended users can continue using Browser Extension API keys
Published 2026-03-13 · Analyzed
2.7EPSS 0.003
CVE-2026-45403
AnythingLLM: filesystem-copy-file follows nested symlinks and copies files from outside the allowed directory
Published 2026-05-28 · Analyzed
2.5EPSS 0.002
← Prev2 / 2