CVE-2024-0765

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
03/03/2024
Last modified:
08/01/2025

Description

As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip and read that export that would enable you do exfiltrate data of the system at that save state.<br /> <br /> This would require the attacked to be granted explicit access to the system, but they can do this at any role. Additionally, post-download, the data is deleted so no evidence would exist that the exfiltration occured.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* 1.0.0 (excluding)