In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as deleting all data from the workspace.
References
Link | Resource |
---|---|
https://github.com/mintplex-labs/anything-llm/commit/9bfe477f10b188bfe3508ac29105df80d4522ece | Patch |
https://huntr.com/bounties/dbde1c71-7aa5-46f6-847a-d89793cf97a9 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
15 Jul 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
First Time |
Mintplexlabs
Microsoft windows Mintplexlabs anythingllm Desktop Microsoft |
|
Summary |
|
|
CPE | cpe:2.3:a:mintplexlabs:anythingllm_desktop:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
References | () https://github.com/mintplex-labs/anything-llm/commit/9bfe477f10b188bfe3508ac29105df80d4522ece - Patch | |
References | () https://huntr.com/bounties/dbde1c71-7aa5-46f6-847a-d89793cf97a9 - Exploit, Third Party Advisory |
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-07-15 15:15
NVD link : CVE-2024-8196
Mitre link : CVE-2024-8196
CVE.ORG link : CVE-2024-8196
JSON object : View
Products Affected
mintplexlabs
- anythingllm_desktop
microsoft
- windows
CWE
CWE-306
Missing Authentication for Critical Function