Mintplexlabs Security Vulnerabilities (CVEs)

Track 33 security vulnerabilities affecting Mintplexlabs products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

8 Critical
18 High
7 Medium
🔔 Get Alerts for Mintplexlabs
CVE-2026-21484 5.3

This vulnerability in AnythingLLM allows attackers to determine whether specific usernames exist in the system by observing different error messages f...

Jan 3, 2026
CVE-2025-63390 5.3

An authentication bypass vulnerability in AnythingLLM v1.8.5 allows unauthenticated attackers to enumerate and retrieve detailed information about all...

Dec 18, 2025
CVE-2024-8196 9.8

The Anything-LLM desktop application for Windows opens port 3001 on all network interfaces (0.0.0.0) without authentication by default. This allows at...

Mar 20, 2025
CVE-2024-8248 7.2

A path traversal vulnerability in the normalizePath function of mintplex-labs/anything-llm allows attackers to read and write arbitrary files within t...

Mar 20, 2025
CVE-2024-8249 7.5

This vulnerability allows unauthenticated attackers to crash the Anything-LLM server by sending malformed JSON payloads to the embeddable chat API end...

Mar 20, 2025
CVE-2024-8251 5.3

A Prisma injection vulnerability in mintplex-labs/anything-llm allows attackers to bypass access controls by sending specially crafted JSON to the /em...

Mar 20, 2025
CVE-2024-7771 6.5

A denial-of-service vulnerability in Dockerized anything-llm allows attackers to crash the entire site instance by uploading an audio file with a very...

Mar 20, 2025
CVE-2024-6842 7.5

This vulnerability allows unauthenticated attackers to access the /setup-complete API endpoint in Anything-LLM version 1.5.5, exposing sensitive syste...

Mar 20, 2025
CVE-2024-7783 7.5

This vulnerability in anything-llm's single user mode exposes user passwords in plaintext within JWT bearer tokens. Attackers who obtain these tokens ...

Oct 29, 2024
CVE-2024-3279 9.1

This vulnerability allows unauthenticated attackers to import malicious database files into the anything-llm application, potentially deleting or spoo...

Aug 12, 2024
CVE-2024-5216 7.5

This vulnerability in mintplex-labs/anything-llm allows attackers to cause a Denial of Service by creating users with excessively large usernames, whi...

Jun 25, 2024
CVE-2024-5208 6.5

An uncontrolled resource consumption vulnerability in the 'upload-link' endpoint of mintplex-labs/anything-llm allows authenticated users with Manager...

Jun 19, 2024
CVE-2024-5211 7.2

A path traversal vulnerability in mintplex-labs/anything-llm allows authenticated managers to bypass path normalization and access, delete, or overwri...

Jun 12, 2024
CVE-2024-3150 8.8

This vulnerability allows users with Default or Manager roles in mintplex-labs/anything-llm to escalate their privileges to Administrator by exploitin...

Jun 6, 2024
CVE-2024-3166 9.6

A Cross-Site Scripting (XSS) vulnerability in mintplex-labs/anything-llm allows attackers to execute arbitrary JavaScript code by exploiting the appli...

Jun 6, 2024
CVE-2024-3102 5.3

A JSON injection vulnerability in the anything-llm application allows attackers to perform brute force attacks against the login system without knowin...

Jun 6, 2024
CVE-2024-3110 8.7

A stored XSS vulnerability in anything-llm allows attackers with manager role to inject malicious JavaScript via crafted URLs. When an admin clicks th...

Jun 6, 2024
CVE-2024-3033 9.4

An improper authorization vulnerability in the mintplex-labs/anything-llm application allows unauthenticated users to perform destructive actions on t...

Jun 6, 2024
CVE-2024-3152 8.8

CVE-2024-3152 affects mintplex-labs/anything-llm, allowing attackers to escalate privileges to admin, read/delete arbitrary files, and perform SSRF at...

Jun 6, 2024
CVE-2024-4084 7.5

This SSRF vulnerability in mintplex-labs/anything-llm allows attackers to bypass IP filtering and access internal network resources by using alternati...

Jun 5, 2024
CVE-2024-4284 4.9

A vulnerability in mintplex-labs/anything-llm allows authenticated users with manager or admin privileges to cause a denial of service by modifying a ...

May 19, 2024
CVE-2024-3028 7.2

This vulnerability in mintplex-labs/anything-llm allows attackers to read and delete arbitrary files on the server by manipulating the 'logo_filename'...

Apr 16, 2024
CVE-2024-0404 9.1

This CVE describes a mass assignment vulnerability in the Anything-LLM software that allows attackers to create administrative accounts by interceptin...

Apr 16, 2024
CVE-2024-3101 7.2

This vulnerability in mintplex-labs/anything-llm allows attackers to disable Multi-User Mode via improper input validation, enabling them to create ne...

Apr 10, 2024
CVE-2024-3025 9.9

This path traversal vulnerability in mintplex-labs/anything-llm allows attackers to read or delete files outside the intended directory by manipulatin...

Apr 10, 2024
CVE-2024-0795 7.2

This vulnerability allows attackers with admin or manager roles in Anything LLM to create new admin users without proper backend authentication, enabl...

Mar 2, 2024
CVE-2024-0763 8.1

CVE-2024-0763 is a path traversal vulnerability in Anything-LLM that allows authenticated users to delete arbitrary folders recursively on the server....

Feb 27, 2024
CVE-2024-0759 7.5

This vulnerability in AnythingLLM allows authenticated users with manager or admin permissions to discover and potentially access other internal servi...

Feb 27, 2024
CVE-2024-0439 8.8

This CVE describes an improper privilege management vulnerability in Anything-LLM where managers can bypass UI restrictions and modify restricted sett...

Feb 26, 2024
CVE-2024-0455 7.5

This vulnerability in AnythingLLM's web scraper allows authorized users (managers, admins, or single users) to access AWS EC2 instance metadata servic...

Feb 26, 2024
CVE-2023-5832 9.1

CVE-2023-5832 is an improper input validation vulnerability in the Anything-LLM software that allows attackers to execute arbitrary code or cause deni...

Oct 30, 2023
CVE-2023-4899 8.8

This SQL injection vulnerability in the Anything-LLM software allows attackers to execute arbitrary SQL commands through user input. It affects all de...

Sep 12, 2023
CVE-2023-4897 9.8

This vulnerability allows attackers to perform relative path traversal attacks in the Anything-LLM software, enabling unauthorized access to files out...

Sep 11, 2023

Why Monitor Mintplexlabs Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 33+ known vulnerabilities affecting Mintplexlabs products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Mintplexlabs packages in under 60 seconds. No agents required - completely agentless scanning that works across Mintplexlabs deployments.

Free vulnerability database: Access detailed information about every Mintplexlabs CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Mintplexlabs CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Mintplexlabs CVEs Free