PT-2026-4834 · Unknown+1 · Anything-Llm+1

Lagongit

·

Published

2026-01-26

·

Updated

2026-03-17

·

CVE-2026-24477

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AnythingLLM versions prior to 1.10.0
Description AnythingLLM is an application that converts content into context for use with Large Language Models (LLMs). If configured to use Qdrant as the vector database with an API key, versions prior to 1.10.0 expose the QdrantApiKey in plain text to unauthenticated users via the /api/setup-complete endpoint. Compromise of the QdrantApiKey grants an unauthenticated attacker full read/write access to the Qdrant vector database instance used by AnythingLLM, potentially leading to the leakage of confidential uploaded documents.
Recommendations Update to version 1.10.0 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-24477
GHSA-GM94-QC2P-XCWF

Affected Products

Anything-Llm
Qdrant