PT-2025-12169 · Unknown · Anything-Llm

Published

2025-03-20

·

Updated

2025-07-15

·

CVE-2024-6842

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions mintplex-labs/anything-llm version 1.5.5
Description The issue allows unauthorized users to access sensitive system settings through the "/setup-complete" API endpoint. The data returned by the currentSettings function includes sensitive information, such as API keys for search engines, which can be exploited by attackers to steal these keys and cause loss of user assets.
Recommendations For version 1.5.5, consider disabling access to the "/setup-complete" API endpoint until a patch is available to prevent unauthorized access to sensitive system settings. Restrict the use of the currentSettings function to authorized users only to minimize the risk of exploitation.

Exploit

Fix

Missing Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-6842

Affected Products

Anything-Llm