CVE-2024-8196

CVSS 3.0 Score 9.8 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 306

Summary

CVE-2024-8196 is a vulnerability affecting the desktop version of anything-llm v1.5.11 by mintplex-labs for Windows. By default, the application opens server port 3001 on all interfaces without requiring authentication. An attacker can exploit this weakness and gain unauthorized full backend access, potentially leading to the deletion or manipulation of all data within the workspace.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share