CVE-2024-0550

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-0550
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-0550.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-0550
Published
2024-02-28T05:15:08Z
Modified
2025-07-01T15:22:30Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

A user who is privileged already manager or admin can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files.

The attacker would have to have been granted privileged permissions to the system before executing this attack.

References

Affected packages

Git / github.com/mintplex-labs/anything-llm

Affected ranges

Type
GIT
Repo
https://github.com/mintplex-labs/anything-llm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed