CVE-2024-8249

mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the API for the embeddable chat functionality. An attacker can exploit this vulnerability by sending a malformed JSON payload to the API endpoint, causing a server crash due to an uncaught exception. This issue is fixed in version 1.2.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*

History

15 Jul 2025, 15:17

Type Values Removed Values Added
CPE cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*
Summary
  • (es) La versión git 6dc3642 de mintplex-labs/anything-llm contiene una vulnerabilidad de denegación de servicio (DoS) no autenticada en la API para la funcionalidad de chat integrable. Un atacante puede explotar esta vulnerabilidad enviando una carga JSON malformada al endpoint de la API, lo que provoca un fallo del servidor debido a una excepción no detectada. Este problema se solucionó en la versión 1.2.2.
First Time Mintplexlabs
Mintplexlabs anythingllm
References () https://github.com/mintplex-labs/anything-llm/commit/548da9ade30368289c5beaf0a8ee2ed2b5c1d81c - () https://github.com/mintplex-labs/anything-llm/commit/548da9ade30368289c5beaf0a8ee2ed2b5c1d81c - Patch
References () https://huntr.com/bounties/2fb0c93f-5bc1-4212-bdca-292db7c6951f - () https://huntr.com/bounties/2fb0c93f-5bc1-4212-bdca-292db7c6951f - Exploit, Third Party Advisory

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-15 15:17


NVD link : CVE-2024-8249

Mitre link : CVE-2024-8249

CVE.ORG link : CVE-2024-8249


JSON object : View

Products Affected

mintplexlabs

  • anythingllm
CWE
CWE-248

Uncaught Exception