A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the model's API key and base path, leading to potential API key leakage and denial of service on chats.
References
Link | Resource |
---|---|
https://github.com/mintplex-labs/anything-llm/commit/8d302c3f670c582b09d47e96132c248101447a11 | Patch |
https://huntr.com/bounties/ad3c9e76-679d-4775-b203-96947ff73551 | Exploit Third Party Advisory |
Configurations
History
11 Jul 2025, 20:43
Type | Values Removed | Values Added |
---|---|---|
First Time |
Mintplexlabs anythingllm
Mintplexlabs |
|
CPE | cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* | |
References | () https://github.com/mintplex-labs/anything-llm/commit/8d302c3f670c582b09d47e96132c248101447a11 - Patch | |
References | () https://huntr.com/bounties/ad3c9e76-679d-4775-b203-96947ff73551 - Exploit, Third Party Advisory | |
Summary |
|
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-07-11 20:43
NVD link : CVE-2024-10109
Mitre link : CVE-2024-10109
CVE.ORG link : CVE-2024-10109
JSON object : View
Products Affected
mintplexlabs
- anythingllm
CWE
CWE-863
Incorrect Authorization