CVE-2024-7771
CVSS 3.0 Score 6.5 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 400
Summary
CVE-2024-7771 is a denial-of-service vulnerability impacting the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92). By uploading an audio file with an extremely low sample rate, attackers can cause the site instance to crash. This issue is due to the localWhisper implementation, which struggles to resample the audio file from 1 Hz to 16000 Hz, resulting in excess memory consumption. Ultimately, the Docker instance is terminated by the instance manager.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.