Privilege Escalation and Local File Inclusion in mintplex-labs/anything-llm
Published Jun 6, 2024
8.8
HIGHCVSS 3.1
EPSS 0.57%
Description
mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit these vulnerabilities to escalate privileges from a default user role to an admin role, read and delete arbitrary files on the system, and perform Server-Side Request Forgery (SSRF) attacks. The vulnerabilities are present in the `/request-token`, `/workspace/:slug/thread/:threadSlug/update`, `/system/remove-logo`, `/system/logo`, and collector's `/process` endpoints. These issues are due to the application's failure to properly validate user input before passing it to `prisma` functions and other critical operations. Affected versions include the latest version prior to 1.0.0.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<1.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mintplex-Labs | Mintplex-Labs/anything-Llm | n/a |
|
- < 1.0.0
-
- Version 0.0.1StatusaffectedConstraints<1.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mintplexlabs | Anythingllm | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://github.com/mintplex-labs/anything-llm/commit/200bd7f0615347ed2efc07903d510e5a208b0afc Patch
- https://huntr.com/bounties/46034fa0-d623-49f8-8ee8-390390181373 ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/mintplex-labs/anything-llm/commit/200bd7f0615347ed2efc07903d510e5a208b0afc | Patch | |
| https://huntr.com/bounties/46034fa0-d623-49f8-8ee8-390390181373 | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.