mintplexlabs anythingllm
66 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
AgentFlows co/setup-complete API endpoint allows unauthorized users to access sensitive supload-link endpoint of mintplex-labs/anything-llm. This vulnernormalizePath() function, intendedmintplex-labs/anything-llm application, specifically within the username parameter/api/invite/:code endpoint of the mintplex-labs/anything-llm repository, allowing/export-data endpoint of the system amanager or admin can set their profile picture via the frontend API using a relative filepath