CVE-2024-0795: Mintplexlabs Anythingllm
High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.
If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have elevated privileges on the instance
Affected products
- Mintplexlabs Anythingllm: before 1.0.0 (fixed in 1.0.0)
Published 2024-03-02. Last modified 2026-06-17.