CVE-2024-0549
Severity CVSS v4.0:
Pending analysis
Type:
CWE-23
Relative Path Traversal
Publication date:
16/04/2024
Last modified:
09/07/2025
Description
mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete files and folders within the filesystem, including critical database files such as 'anythingllm.db'. The vulnerability stems from insufficient input validation and normalization in the handling of file and folder deletion requests. Successful exploitation results in the compromise of data integrity and availability.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* | 1.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/mintplex-labs/anything-llm/commit/026849df0224b6a8754f4103530bc015874def62
- https://huntr.com/bounties/fcb4001e-0290-4b78-a2f0-91ee5d20cc72
- https://github.com/mintplex-labs/anything-llm/commit/026849df0224b6a8754f4103530bc015874def62
- https://huntr.com/bounties/fcb4001e-0290-4b78-a2f0-91ee5d20cc72



