Bounties
Partners
Community
Info
mintplex-labs / anything-llm
Project repository
The all-in-one Desktop & Docker AI application with built-in RAG, AI agents, and more.
Submit a report
FIRST INTERACTION
WITHIN
3 DAYS
REVIEW
WITHIN
19 DAYS
FIX
WITHIN
438 DAYS
Changing the "ID" parameter in the user cookie allows loading the profile pictur...
Mar 4th 2025
cyber-wo0dy
•
Medium
Medium
•
CVE-2024-13060
CVE-2024-13060
Path traversal, lead to arbitrary file write, lead to remote code execution
Feb 9th 2025
oicu0619
•
High
•
$450
High
•
$450
•
CVE-2024-13059
CVE-2024-13059
Redos (Regular Expression Denial of Service)
Oct 28th 2024
oicu0619
•
informative
Medium
Sensitive Data Exposure via API
Oct 28th 2024
1d8
•
informative
High
Stored Cross-Site Scripting (XSS) Within Profile Images
Sep 5th 2024
1d8
•
duplicate
High
Server-Side Request Forgery (SSRF) Via Workspace Document Upload
Sep 5th 2024
1d8
•
duplicate
Medium
Low privilege user can modify model settings, leading to LLM API key leakage, an...
Dec 2nd 2024
oicu0619
•
High
•
$450
High
•
$450
•
CVE-2024-10109
CVE-2024-10109
DoS attack in Upload document
Sep 19th 2024
vishnuraj-r
•
informative
Medium
Data leak through CORS misconfiguration
Aug 31st 2024
h2oa
•
not applicable
CSRF lead to take over admin account
Aug 31st 2024
h2oa
•
not applicable
Directly take user json to prisma library where clause, aka prisma injection
Nov 3rd 2024
oicu0619
•
Medium
•
$120
Medium
•
$120
•
CVE-2024-8251
CVE-2024-8251
unauth DOS on embed chat
Nov 7th 2024
oicu0619
•
High
•
$450
High
•
$450
•
CVE-2024-8249
CVE-2024-8249
Path traversal lead to arbitrary file write/read in storage dir, further lead to...
Nov 14th 2024
oicu0619
•
duplicate
High
•
CVE-2024-8248
CVE-2024-8248
Origin mirroring on API-endpoints allow CSRF
Aug 14th 2024
patrik-ha
•
informative
High
Collector endpoint for parsing Office files vulnerable to ZIP-bomb
Aug 22nd 2024
patrik-ha
•
informative
Medium
anything LLM desktop version on windows open server port with no authentication...
Oct 22nd 2024
oicu0619
•
Critical
•
$900
Critical
•
$900
•
CVE-2024-8196
CVE-2024-8196
SSRF in Document upload allows Access to Cloud Instance Metadata
Aug 14th 2024
karthik983
•
duplicate
Medium
Improper Session Management: JWT Token Not Invalidated After Logout
Aug 13th 2024
karthik983
•
informative
High
Access to internal network assets via SSRF through DNS resolving
Aug 27th 2024
winters0x64
•
duplicate
High
SSRF in /upload-link endpoint allows reading of Internal network assets
Aug 27th 2024
winters0x64
•
informative
Medium
Improper Storage of Sensitive information in Bearer Token
Oct 2nd 2024
karthik983
•
Medium
•
$75
Medium
•
$75
•
CVE-2024-7783
CVE-2024-7783
Cross-Site Scripting Via Workspace Image Upload
Sep 28th 2024
1d8
•
duplicate
High
Reflected XSS Vulnerability via SVG File Upload in AnythingLLM
Aug 12th 2024
devsecops-47
•
duplicate
Medium
Denial of service by uploading audio file with low sample rate
Sep 26th 2024
patrik-ha
•
Medium
•
$75
Medium
•
$75
•
CVE-2024-7771
CVE-2024-7771
User with manager role can delete other users profile pictures
Jul 17th 2024
noizybit
•
informative
Medium
Unauthorized user can get full access to "anythingllm.db" system database, read...
Jan 1st 1970
noizybit
•
High
•
$630
High
•
$630
•
CVE-2024-10513
CVE-2024-10513
SSRF bypass using redirect
Aug 27th 2024
lager1
•
informative
High
Exposure sensitive info via specific API
Jul 23rd 2024
rpie9
•
High
•
$450
High
•
$450
•
CVE-2024-6842
CVE-2024-6842
Pixel Flood Attack Vulnerability in Image Upload Feature
Jul 17th 2024
saimanikanta1992
•
informative
Medium
Site wide path traversal bypass for the normalizePath() on windows installations
Aug 12th 2024
saymenn
•
informative
High
SSRF protection bypass
Jun 6th 2024
saymenn
•
self closed
Denial of Service in users Home Page including admin's, and in Workspaces settin...
May 23rd 2024
mnqazi
•
informative
Medium
Open Redirect
May 22nd 2024
aaron911
•
informative
High
Denial of Service in User Management Prevents Admin from Editing, Suspending, or...
Jun 25th 2024
mnqazi
•
High
•
$450
High
•
$450
•
CVE-2024-5216
CVE-2024-5216
Hardcoded Plaintext Passwords in JWT Tokens in Single user mode
May 22nd 2024
mnqazi
•
informative
High
Wrong Icon causes UI rendering failure
Jun 10th 2024
aaron911
•
informative
Medium
•
CVE-2024-5214
CVE-2024-5214
Multiple Stored XSS via Picture Upload's leading to Account takeover in mintplex...
May 22nd 2024
alfinj0se
•
duplicate
High
Security Headers in Express.js Application
May 22nd 2024
abdolzx
•
informative
Medium
Password hash of user returned in responses
Jun 20th 2024
acciobugs
•
Medium
•
$75
Medium
•
$75
•
CVE-2024-5213
CVE-2024-5213
ssrf bug to access internal network
May 22nd 2024
d47secc
•
informative
High
Path traversal to Arbitrary file Read/Delete/Overwrite, DoS attack and admin acc...
Jun 12th 2024
noizybit
•
Critical
•
$1260
Critical
•
$1260
•
CVE-2024-5211
CVE-2024-5211
Response tampering lead to delele/update thread of another user
Jun 12th 2024
d47secc
•
not applicable
(Still exploitable) Shutting down the server by sending invalid upload request
Jun 19th 2024
sev-hack
•
Medium
•
$75
Medium
•
$75
•
CVE-2024-5208
CVE-2024-5208
Potential clickjacking through iframes
Apr 25th 2024
patrik-ha
•
informative
Medium
Frameable response (potential Clickjacking)
Jun 10th 2024
mnqazi
•
informative
Medium
•
CVE-2024-4206
CVE-2024-4206
ssrf bug to scan internet network
Apr 25th 2024
happypwn1337
•
duplicate
Critical
Upload HTML file lead to Stored XSS
Apr 25th 2024
h2oa
•
duplicate
High
ssrf bug to access internal network
Apr 25th 2024
t1m0n0
•
informative
Critical
SSRF leads to cloud data leakage in azure
Apr 25th 2024
c0ldb00t3r
•
informative
High
Admin account takeover
Apr 27th 2024
noizybit
•
informative
High
User with manager role is able to create new Administrator accounts
May 20th 2024
noizybit
•
High
•
$450
High
•
$450
•
CVE-2024-4287
CVE-2024-4287
User modification allows for data modification
May 26th 2024
lager1
•
Medium
•
$90
Medium
•
$90
•
CVE-2024-4286
CVE-2024-4286
Denial of service by assigning specific user id
May 19th 2024
lager1
•
Medium
•
$90
Medium
•
$90
•
CVE-2024-4284
CVE-2024-4284
HTML injection in chat enables users to unknowingly upload files to the attacker...
Apr 3rd 2024
mnqazi
•
informative
Medium
Unrestricted Profile Picture Upload leads to stored XSS by uploading malicious S...
Apr 3rd 2024
mnqazi
•
informative
Critical
Stored XSS in Account avatar upload
Apr 1st 2024
nduy2110
•
duplicate
Critical
Default / manager user can escalate their privileges to Administrator
May 16th 2024
noizybit
•
High
•
$450
High
•
$450
•
CVE-2024-3150
CVE-2024-3150
Prisma Filter Injection allow user enumeration
Mar 29th 2024
nduy2110
•
informative
High
SSRF bug to access internal network
Mar 29th 2024
nduy2110
•
duplicate
High
SSRF in the upload link feature leads to accessing internal Collector API and es...
May 19th 2024
noizybit
•
Critical
•
$900
Critical
•
$900
•
CVE-2024-3149
CVE-2024-3149
Observable Timing Discrepancy
Mar 27th 2024
dievus
•
informative
Medium
Server-Side Request Forgery
Mar 29th 2024
dievus
•
duplicate
High
Denial of service using the `/api/migrate` endpoint
Mar 27th 2024
lager1
•
informative
Medium
JSON Web Token Tampering Denial of Service
Mar 25th 2024
dievus
•
duplicate
High
Improper input validation in Collector API leads to unauthenticated arbitary fil...
Mar 27th 2024
noizybit
•
informative
Critical
Stored XSS to admin account takeover
May 2nd 2024
noizybit
•
High
•
$450
High
•
$450
•
CVE-2024-3110
CVE-2024-3110
Improper authorization check leads to deleting and erasing all data in VectorDB
May 3rd 2024
noizybit
•
Critical
•
$900
Critical
•
$900
•
CVE-2024-3033
CVE-2024-3033
Logo upload function allows uploading arbitrary files
Mar 29th 2024
kr3ww
•
informative
High
username enumeration vulnerability
Mar 27th 2024
james-niki
•
informative
Medium
A user can crash the entire app causing a DoS by only sending a message in chat...
Mar 27th 2024
noizybit
•
self closed
'collector/utils/url/index.js' sanitization on IP in 'isInvalidIp' can by bypass...
Mar 29th 2024
retr0reg
•
informative
Medium
Privilege escalation from default to role to admin and then LFI and more
May 1st 2024
ozelis
•
High
•
$450
High
•
$450
•
CVE-2024-3152
CVE-2024-3152
Full read SSRF via within docker port scan using URL redirection.
Mar 29th 2024
ph4nt0m-py
•
duplicate
Critical
Cross site scripting using the fetch website feature
Apr 21st 2024
lager1
•
Low
•
$15
Low
•
$15
•
CVE-2024-3166
CVE-2024-3166
Blind XSS bug in Chat
Mar 8th 2024
tuna18dv
•
informative
Medium
Race Condition in /api/workspace/:slug/stream-chat
Mar 27th 2024
ch1nhpd
•
informative
Medium
Insufficient session expiration
Mar 27th 2024
h2oa
•
duplicate
Medium
Default role users can view the settings interface of admin/manager role users
Mar 29th 2024
h2oa
•
duplicate
Medium
SSRF bypass using redirect
Mar 29th 2024
lager1
•
duplicate
Medium
SSRF access to internal network assets
Mar 29th 2024
bl0ckbeard
•
duplicate
High
DOS attack in Just me mode
Mar 30th 2024
trongphuc12
•
High
•
$450
High
•
$450
•
CVE-2024-3569
CVE-2024-3569
No rate limit at login form
Mar 27th 2024
h2oa
•
duplicate
High
No rate limit on login form
Mar 27th 2024
kirtiso
•
informative
Medium
Prompt Injection Leads to Information Disclosure in Anything LLM Prompt
Mar 27th 2024
lohigowdain
•
not applicable
SSRF bypass on `POST /api/workspace/:slug/upload-link`
Mar 29th 2024
lager1
•
duplicate
High
Injection to query engine using username
Mar 29th 2024
lager1
•
informative
High
The manager role can update the value of an arbitrary label in SystemSettings.
Mar 1st 2024
trongphuc12
•
duplicate
Critical
Remote code execution using environment variables
Apr 16th 2024
lager1
•
Critical
•
$1620
Critical
•
$1620
•
CVE-2024-3104
CVE-2024-3104
JSON Injection in login
Apr 16th 2024
trongphuc12
•
Medium
•
$75
Medium
•
$75
•
CVE-2024-3102
CVE-2024-3102
HTML Injection + Server-Side Template Injection (SSTI)
Mar 12th 2024
lohigowdain
•
duplicate
Medium
Path traversal via logo_filename leads to delete and read any files on the syste...
Mar 1st 2024
nhienit2010
•
duplicate
Critical
Race Condition when submit question for AI
Mar 27th 2024
oiiwroo
•
informative
Medium
Allowing SVG file upload in chatbot logo and user avatar upload function leads t...
Mar 29th 2024
tuna18dv
•
informative
High
Race Condition when accept invite link
Mar 27th 2024
oiiwroo
•
duplicate
Medium
SSRF in /api/workspace/:slug/upload-link function via redirect
Mar 29th 2024
nhienit2010
•
duplicate
Critical
Application doesn't revoke api-key after enable multi-user mode
Mar 27th 2024
trongphuc12
•
duplicate
Critical
Escalation of privilege vulnerability allows access to administrative functions...
Mar 29th 2024
tuna18dv
•
informative
High
EXIF metadata not stripped from JPG team logos
Mar 8th 2024
oiiwroo
•
informative
Medium
CSV injection
Mar 27th 2024
oiiwroo
•
duplicate
Medium
Priv escalation - an Admin user can send an API request to suspend all other Adm...
Feb 29th 2024
bl0ckbeard
•
self closed
Race Condition in /api/invite/
Mar 27th 2024
ch1nhpd
•
informative
Medium
SSRF in /api/workspace/:slug/upload-link function bypass CVE-2024-0759
Mar 29th 2024
nhienit2010
•
duplicate
Critical
Dos for all server by edit JWT in Authorization header
Mar 25th 2024
oiiwroo
•
duplicate
High
HTML injection [mintplex-labs/anything-llm]
Mar 8th 2024
kirtiso
•
duplicate
High
SSTI in chat in mintplex-labs/anything-llm
Mar 12th 2024
kirtiso
•
informative
Critical
SSRF check bypassed by Unicoding the IP address
Mar 29th 2024
hiu240900
•
duplicate
Critical
Shutting down the server by sending invalid upload request
Apr 21st 2024
hiu240900
•
Medium
•
$75
Medium
•
$75
•
CVE-2024-3153
CVE-2024-3153
AnythingLLM still has SSRF vulnerability
Jun 5th 2024
wh0amitz
•
High
•
$450
High
•
$450
•
CVE-2024-4084
CVE-2024-4084
Deactivate Multi-User Mode and Delete All Users
Apr 16th 2024
mvlttt
•
Critical
•
$900
Critical
•
$900
•
CVE-2024-3029
CVE-2024-3029
Failure to Invalidate Session On Password Reset and/or Change of invited user m...
Feb 29th 2024
kirtiso
•
informative
High
User can read and delete arbitrary files
Apr 16th 2024
mvlttt
•
High
•
$450
High
•
$450
•
CVE-2024-3028
CVE-2024-3028
XSS via javascript scheme at "Custom Footer Icons" function
Feb 29th 2024
hiu240900
•
informative
Medium
Users can escalate privileges by deactivating 'Multi-User Mode'.
Apr 13th 2024
mvlttt
•
Medium
•
$75
Medium
•
$75
•
CVE-2024-3101
CVE-2024-3101
Denial of Service (DoS). Due to Unrestricted Workspace Name Length
Feb 29th 2024
dailybee13
•
informative
Medium
Server Side Request forgery (SSRF) in upload-link endpoint
Feb 29th 2024
m0kr4n3
•
informative
Medium
Stored XSS on chat due to lack of output encoding
Mar 8th 2024
ph4nt0m-py
•
informative
Medium
Server Side Request Forgery leads to extract AWS Metadata (No proper fix impleme...
Mar 29th 2024
ph4nt0m-py
•
duplicate
Critical
csv/formula injection
Mar 27th 2024
ranjit-git
•
informative
Medium
removed user can see embed chat details after removed from team.
Mar 27th 2024
ranjit-git
•
not applicable
removed user still can perform all operation with api key
Mar 27th 2024
ranjit-git
•
informative
Critical
privilege escalation bug to add feedback to any chat
Mar 27th 2024
ranjit-git
•
informative
Medium
non-admin user can delete workspace
Mar 27th 2024
ranjit-git
•
informative
High
Mass assignment that leads to privilege escalation attack
Apr 5th 2024
tauron3
•
High
•
$450
High
•
$450
•
CVE-2024-3283
CVE-2024-3283
Arbitrary file deletion / reading via path traversal in logo photo upload and do...
Mar 25th 2024
williwollo
•
Critical
•
$900
Critical
•
$900
•
CVE-2024-3025
CVE-2024-3025
Race Condition in accepting user invites
May 6th 2024
rook1337
•
Medium
•
$75
Medium
•
$75
•
CVE-2024-2913
CVE-2024-2913
ssrf fix bypass
Feb 7th 2024
ranjit-git
•
informative
Critical
Anonymous access to import endpoint leads to anythingllm.db deletion/spoofing
Aug 9th 2024
dastaj
•
Critical
•
$1500
Critical
•
$1500
•
CVE-2024-3279
CVE-2024-3279
Path traversal leads to anythingllm.db deletion
Apr 16th 2024
dastaj
•
High
•
$750
High
•
$750
•
CVE-2024-0549
CVE-2024-0549
Arbitrary file reading via path traversal in profile photo loading feature
Feb 28th 2024
williwollo
•
Critical
•
$1500
Critical
•
$1500
•
CVE-2024-0550
CVE-2024-0550
Improper input validation leads to arbitrary folder deletion (recursively)
Feb 27th 2024
raltheo
•
High
•
$1500
High
•
$1500
•
CVE-2024-0763
CVE-2024-0763
Improper input validation leads to arbitrary file deletion
Jan 19th 2024
raltheo
•
informative
High
Unauthorized access to anythingllm.db database exports
Feb 27th 2024
dastaj
•
High
•
$750
High
•
$750
•
CVE-2024-0551
CVE-2024-0551
Privilege Escalation and Unauthorized User Data Manipulation
Jan 22nd 2024
williwollo
•
informative
High
upload file to server without authentication
Jan 19th 2024
ranjit-git
•
informative
High
ssrf bug to access internal network
Feb 27th 2024
ranjit-git
•
High
•
$1500
High
•
$1500
•
CVE-2024-0759
CVE-2024-0759
Improper privilege management between admin and manager roles
Feb 25th 2024
dastaj
•
High
•
$750
High
•
$750
•
CVE-2024-0439
CVE-2024-0439
SSRF - reading local files, env secrets, AWS metadata endpoint
Feb 25th 2024
dastaj
•
Critical
•
$1500
Critical
•
$1500
•
CVE-2024-0440
CVE-2024-0440
Insecure input & output handling - XSS leading to admin account takeover
Jan 12th 2024
dastaj
•
informative
High
xss bug in chat
Feb 25th 2024
ranjit-git
•
High
•
$750
High
•
$750
•
CVE-2024-0435
CVE-2024-0435
session is active even after user has been logged out of his account
Jan 12th 2024
ranjit-git
•
informative
High
privilege escalation bug to delete the uploaded document
Feb 25th 2024
ranjit-git
•
High
•
$900
High
•
$900
•
CVE-2024-0798
CVE-2024-0798
timing attack to guess the authtoken
Feb 25th 2024
ranjit-git
•
High
•
$750
High
•
$750
•
CVE-2024-0436
CVE-2024-0436
privilege escalation bug to change workspace name
Jan 22nd 2024
ranjit-git
•
informative
High
Mass assignment in account creation from invitation
Apr 16th 2024
dastaj
•
Critical
•
$1500
Critical
•
$1500
•
CVE-2024-0404
CVE-2024-0404
Unrestricted file upload while changing logo leads to XSS
Jan 19th 2024
rook1337
•
informative
Medium
privilege escalation bug to add higher level user
Jan 22nd 2024
ranjit-git
•
informative
High
default/manager user can get all system database information like username,pas...
Mar 3rd 2024
ranjit-git
•
Critical
•
$1500
Critical
•
$1500
•
CVE-2024-0765
CVE-2024-0765
manager user become admin user
Jan 22nd 2024
ranjit-git
•
informative
High
Command Injection (Input Validation and Representation, Structural)
Jan 19th 2024
azizsec
•
not applicable
ssrf bug to steal aws metadata
Feb 25th 2024
ranjit-git
•
Critical
•
$1500
Critical
•
$1500
•
CVE-2024-0455
CVE-2024-0455
Steal admin authtoken with svg xss
Jan 19th 2024
ranjit-git
•
informative
High
XSS - Stored / Admin account takeover
Feb 24th 2024
raltheo
•
None
None
•
CVE-2024-3570
CVE-2024-3570
Improper acces control / admin account takeover
Mar 2nd 2024
raltheo
•
High
•
$750
High
•
$750
•
CVE-2024-0795
CVE-2024-0795
Admin account TakeOver
Oct 27th 2023
raltheo
•
High
High
•
CVE-2023-5833
CVE-2023-5833
Improper input validation leads to arbitrary file deletion
Oct 27th 2023
charliebailly
•
Critical
Critical
•
CVE-2023-5832
CVE-2023-5832
No permission check /api/system/update-env lead to Account takeover and SQL inj...
Sep 29th 2023
ngbthg101
•
informative
Critical
SQL injection and Authentication bypass
Sep 11th 2023
vvxhid
•
High
High
•
CVE-2023-4898
CVE-2023-4898
SQL injection in slug parameter
Sep 11th 2023
vvxhid
•
High
High
•
CVE-2023-4899
CVE-2023-4899
Relative path traversal
Sep 11th 2023
vvxhid
•
High
High
•
CVE-2023-4897
CVE-2023-4897
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0