CVE-2024-6842
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 200
Summary
CVE-2024-6842 is a vulnerability affecting version 1.5.5 of the mintplex-labs/anything-llm package. The issue lies with the `/setup-complete` API endpoint, which incorrectly grants unauthorized users access to sensitive system settings. This includes the `currentSettings` function, which discloses API keys for search engines. An attacker can exploit this vulnerability to steal these keys, leading to the loss of user assets.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.