PT-2025-12223 · Unknown · Anything-Llm
Published
2025-03-20
·
Updated
2025-07-15
·
CVE-2024-8196
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
mintplex-labs/anything-llm version 1.5.11
Description
The application opens server port 3001 on 0.0.0.0 with no authentication by default, allowing an attacker to gain full backend access. This enables them to perform actions such as deleting all data from the workspace.
Recommendations
For version 1.5.11, consider disabling access to server port 3001 until a patch is available, or implement authentication mechanisms to restrict unauthorized access. As a temporary workaround, restrict access to the backend to minimize the risk of exploitation.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anything-Llm