CRITICAL🇵🇱 Wersja polska

CVE-2024-3033

CVSS 9.4v3.1pub. 2024-06-06upd. 2024-11-21

An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the VectorDB, including resetting the database and deleting specific namespaces, without requiring any authorization or permissions. The issue affects all versions up to and including the latest version, with a fix introduced in version 1.0.0. Exploitation of this vulnerability can lead to complete data loss of document embeddings across all workspaces, rendering workspace chats and embeddable chat widgets non-functional. Additionally, attackers can list all namespaces, potentially exposing private workspace names.

🤖 AI Analysis
How it works

The '/api/v/' endpoint and its sub-paths do not enforce any identity verification or authorization checks, meaning that any remote user without authentication can send requests to them. An attacker can reset the entire VectorDB database, delete selected namespaces, or list all existing namespaces. The absence of access control mechanisms means that no application security measures can prevent these operations.

Impact

An attacker can cause complete data loss of document embeddings across all workspaces, rendering chats in workspaces and chat widgets non-functional. Additionally, it is possible to disclose private workspace names by listing them.

Mitigation & patch

Update the mintplex-labs/anything-llm application to version 1.0.0 or later, which includes the fix (commit bf8df60c02b9ddc7ba682809ca12c5637606393a). Until the update is applied, it is recommended to restrict network access to '/api/v/' endpoints exclusively to trusted hosts using firewall or proxy mechanisms.

Who is affected

All versions of the mintplex-labs/anything-llm application up to and including the last version before the fix; the fix was introduced in version 1.0.0.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
  • Mintplexlabs Anythingllm

    APP
    Mintplexlabs
    < 1.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-32626CRITICAL9.6PL ✓same product

XSS eskalujący do RCE w AnythingLLM Desktop poprzez podatny renderer Electron

CVE-2024-3279CRITICAL9.1PL ✓same product

Nieprawidłowa kontrola dostępu w AnythingLLM — nieautoryzowana manipulacja bazą danych

CVE-2024-3104CRITICAL9.8PL ✓same product

RCE poprzez command injection w Mintplex Labs AnythingLLM

CVE-2024-0404CRITICAL9.1PL ✓same product

Mass assignment w anything-llm umożliwia nieautoryzowane tworzenie kont admin

CVE-2024-3025CRITICAL9.9PL ✓same product

Path Traversal w AnythingLLM — odczyt i usunięcie plików przez logo filename