Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-10109

Опубликовано: 20 мар. 2025
Источник: nvd
CVSS3: 8.3
EPSS Низкий

Описание

A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the model's API key and base path, leading to potential API key leakage and denial of service on chats.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*
Версия до 1.3.1 (исключая)

EPSS

Процентиль: 33%
0.00131
Низкий

8.3 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.3
github
11 месяцев назад

A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the model's API key and base path, leading to potential API key leakage and denial of service on chats.

EPSS

Процентиль: 33%
0.00131
Низкий

8.3 High

CVSS3

Дефекты

CWE-863