CVE-2024-8196 Details
Description
In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as deleting all data from the workspace.
A vulnerability in Mintplex Labs Anything-LLM version 1.5.11 for Windows desktop has been identified, where the application opens server port 3001 on all interfaces (0.0.0.0) without authentication. This exposure allows attackers to gain full access to the backend, potentially leading to actions such as deleting all workspace data.
Users can disable the network discovery feature by setting the 'APP_DISCOVERABLE' environment variable to 'false', which will prevent the application from opening the port on all interfaces. However, this change requires a full restart of the application to take effect.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mintplex-labs/anything-llm/commit/9bfe477f10b188bfe3508ac29105df80d4522ece | [email protected] | Patch |
| https://huntr.com/bounties/dbde1c71-7aa5-46f6-847a-d89793cf97a9 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mintplexlabs anythingllm desktop | < 1.6.5 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2025 | Initial Analysis | [email protected] |
| Mar 20, 2025 | New CVE Received | [email protected] |