A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library. This vulnerability can lead to arbitrary file write, which can subsequently result in remote code execution. The issue arises when the filename transformation introduces '../' sequences, which are not sanitized by multer, allowing attackers with manager or admin roles to write files to arbitrary locations on the server.
History

Wed, 09 Jul 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mintplexlabs
Mintplexlabs anythingllm
Weaknesses CWE-22
CPEs cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*
Vendors & Products Mintplexlabs
Mintplexlabs anythingllm

Tue, 11 Feb 2025 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Feb 2025 19:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library. This vulnerability can lead to arbitrary file write, which can subsequently result in remote code execution. The issue arises when the filename transformation introduces '../' sequences, which are not sanitized by multer, allowing attackers with manager or admin roles to write files to arbitrary locations on the server.
Title Path Traversal in mintplex-labs/anything-llm
Weaknesses CWE-29
References
Metrics cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-02-10T18:53:04.561Z

Updated: 2025-02-10T23:18:49.345Z

Reserved: 2024-12-30T22:28:31.146Z

Link: CVE-2024-13059

cve-icon Vulnrichment

Updated: 2025-02-10T23:18:39.961Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-10T19:15:37.587

Modified: 2025-07-09T15:11:29.243

Link: CVE-2024-13059

cve-icon Redhat

No data.