CVE-2024-0440: Mintplexlabs Anythingllm

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host files and other relatively stored files.

Affected products

Published 2024-02-26. Last modified 2026-06-17.