PT-2024-30188 · Unknown · Anything-Llm

Published

2024-05-20

·

Updated

2025-07-10

·

CVE-2024-4287

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions anything-llm (affected versions not specified)
Description A vulnerability exists in the workspace update process due to improper input validation. The application fails to validate or format JSON data sent in an HTTP POST request to "/api/workspace/:workspace-slug/update", allowing it to be executed as part of a database query without restrictions. This enables users with a manager role to craft a request that includes nested write operations, effectively allowing them to create new Administrator accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-4287

Affected Products

Anything-Llm