CVE-2024-0549

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-0549
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-0549.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-0549
Published
2024-04-16T00:15:07Z
Modified
2024-10-07T23:30:57Z
Summary
[none]
Details

mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete files and folders within the filesystem, including critical database files such as 'anythingllm.db'. The vulnerability stems from insufficient input validation and normalization in the handling of file and folder deletion requests. Successful exploitation results in the compromise of data integrity and availability.

References

Affected packages

Git / github.com/mintplex-labs/anything-llm

Affected ranges

Type
GIT
Repo
https://github.com/mintplex-labs/anything-llm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed