← Back to browse · API

CVE-2024-6842

Severity
HIGH
CVSS
7.5
EPSS
0.30562
Risk score
40.7
CISA KEV
No
PoC
No
Published
2025-03-20
Modified
2025-10-15
First seen
2026-08-07
Aliases
EUVD-2025-6962, GHSA-P868-P9PJ-FVMR
Products
mintplex-labs:mintplex-labs/anything-llm unspecified <1.0.2
Sources
euvd EUVD-2025-6962

Description

In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for search engines, which can be exploited by attackers to steal these keys and cause loss of user assets.

References