PoC Index

CVE-2024-6842

HIGH 7.5EPSS 31.1%

In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for search engines, which can be exploited by attackers to steal these keys and cause loss of user assets.

CVSS v3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
31.10% chance of exploitation in the next 30 days, 98th percentile
Nuclei
high · CWE-200
Published
2025-03-20
Updated
2025-10-15

Nuclei templates (1)

References

Related