PT-2024-15649 · Mintplex · Anything-Llm

Published

2024-04-15

·

Updated

2025-07-09

·

CVE-2024-0549

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions mintplex-labs/anything-llm (affected versions not specified)
Description The issue allows unauthorized attackers with a default role account to perform a relative path traversal attack, enabling them to delete files and folders within the filesystem. This includes critical database files such as anythingllm.db. The vulnerability is caused by insufficient input validation and normalization in the handling of file and folder deletion requests. Successful exploitation results in the compromise of data integrity and availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2024-0549

Affected Products

Anything-Llm