CRITICAL🇵🇱 Wersja polska

CVE-2024-3279

CVSS 9.1v3.0pub. 2024-08-12upd. 2025-10-15

An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous attacker, without an account in the application, to import their own database file, leading to the deletion or spoofing of the existing `anythingllm.db` file. By exploiting this vulnerability, attackers can serve malicious data to users or collect information about them. The vulnerability stems from the application's failure to properly restrict access to the data-import functionality, allowing unauthorized database manipulation.

🤖 AI Analysis
How it works

The AnythingLLM application does not enforce proper access control on the data import function — the endpoint responsible for import is accessible without authentication. An attacker can send a crafted database file to this endpoint, which replaces or deletes the original `anythingllm.db` file. As a result, the application begins operating on data supplied by the attacker instead of the original user data.

Impact

An attacker can replace the application's database, serving malicious or falsified data to all system users, as well as collecting user information. Permanent deletion of existing data is also possible (system integrity and availability are compromised).

Mitigation & patch

Update the application to a version containing the fix introduced in commit 08d33cfd8fc47c5052b6ea29597c964a9da641e2 available in the GitHub repository. Additionally, it is recommended to restrict network access to the AnythingLLM instance only to trusted users until the patch is deployed.

Who is affected

Application mintplex-labs/anything-llm — versions indicated in producer references (fix commit: 08d33cfd8fc47c5052b6ea29597c964a9da641e2)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Mintplexlabs Anythingllm

    APP
    Mintplexlabs
    < 1.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-32626CRITICAL9.6PL ✓same product

XSS eskalujący do RCE w AnythingLLM Desktop poprzez podatny renderer Electron

CVE-2024-3033CRITICAL9.4PL ✓same product

Brak autoryzacji w AnythingLLM — destrukcyjny dostęp do VectorDB

CVE-2024-3104CRITICAL9.8PL ✓same product

RCE poprzez command injection w Mintplex Labs AnythingLLM

CVE-2024-0404CRITICAL9.1PL ✓same product

Mass assignment w anything-llm umożliwia nieautoryzowane tworzenie kont admin

CVE-2024-3025CRITICAL9.9PL ✓same product

Path Traversal w AnythingLLM — odczyt i usunięcie plików przez logo filename