PT-2024-35128 · Unknown · Anything-Llm

Published

2024-06-25

·

Updated

2025-07-15

·

CVE-2024-5216

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions anything-llm (affected versions not specified)
Description A Denial of Service (DoS) condition can occur due to uncontrolled resource consumption. The issue arises from the application's failure to limit the size of username fields, enabling attackers to create users with excessively bulky texts, resulting in the user management panel becoming unresponsive. This prevents administrators from performing critical user management actions and allows malicious users to perpetuate their presence within the system indefinitely, undermining the system's security posture and degrading overall system performance.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2024-5216

Affected Products

Anything-Llm