PT-2025-12043 · Mintplex · Anything-Llm

Published

2025-03-20

·

Updated

2025-07-14

·

CVE-2024-10513

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mintplex-labs/anything-llm versions prior to 1.2.2
Description A path traversal vulnerability exists in the 'document uploads manager' feature, allowing users with the 'manager' role to access and manipulate the 'anythingllm.db' database file. By exploiting the vulnerable endpoint "/api/document/move-files", an attacker can move the database file to a publicly accessible directory, download it, and subsequently delete it. This can lead to unauthorized access to sensitive data, privilege escalation, and potential data loss.
Recommendations For versions prior to 1.2.2, update to version 1.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/api/document/move-files" endpoint until a patch is available. Restrict the 'manager' role to minimize the risk of exploitation.

Exploit

Fix

LPE

Path traversal

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2024-10513

Affected Products

Anything-Llm