PT-2026-4834 · Unknown+1 · Anything-Llm+1
Lagongit
·
Published
2026-01-26
·
Updated
2026-03-17
·
CVE-2026-24477
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AnythingLLM versions prior to 1.10.0
Description
AnythingLLM is an application that converts content into context for use with Large Language Models (LLMs). If configured to use Qdrant as the vector database with an API key, versions prior to 1.10.0 expose the
QdrantApiKey in plain text to unauthenticated users via the /api/setup-complete endpoint. Compromise of the QdrantApiKey grants an unauthenticated attacker full read/write access to the Qdrant vector database instance used by AnythingLLM, potentially leading to the leakage of confidential uploaded documents.Recommendations
Update to version 1.10.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anything-Llm
Qdrant