In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as deleting all data from the workspace.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as deleting all data from the workspace. | |
Title | Missing Authentication for Critical Function in mintplex-labs/anything-llm | |
Weaknesses | CWE-306 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T13:50:28.828Z
Reserved: 2024-08-26T21:50:54.367Z
Link: CVE-2024-8196

Updated: 2025-03-20T13:50:18.511Z

Status : Received
Published: 2025-03-20T10:15:41.490
Modified: 2025-03-20T10:15:41.490
Link: CVE-2024-8196

No data.