In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as deleting all data from the workspace.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Microsoft
Microsoft windows Mintplexlabs Mintplexlabs anythingllm Desktop |
|
CPEs | cpe:2.3:a:mintplexlabs:anythingllm_desktop:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Microsoft
Microsoft windows Mintplexlabs Mintplexlabs anythingllm Desktop |
Thu, 20 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as deleting all data from the workspace. | |
Title | Missing Authentication for Critical Function in mintplex-labs/anything-llm | |
Weaknesses | CWE-306 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:11:34.868Z
Updated: 2025-03-20T13:50:28.828Z
Reserved: 2024-08-26T21:50:54.367Z
Link: CVE-2024-8196

Updated: 2025-03-20T13:50:18.511Z

Status : Analyzed
Published: 2025-03-20T10:15:41.490
Modified: 2025-07-15T15:15:09.153
Link: CVE-2024-8196

No data.