Improper Authorization in mintplex-labs/anything-llm
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.5%
exploitation probability
0.5%top 63% of all CVEs
observed exploitation
nono source reports it
A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie. This issue is present in versions prior to 1.3.1.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
mintplex-labs · mintplex-labs/anything-llm