CVE-2024-8196
CVSS 3.0 Score 9.8 of 10 (critical)
Details
Published Mar 20, 2025
CWE ID 306
Summary
CVE-2024-8196 is a vulnerability affecting the desktop version of anything-llm v1.5.11 by mintplex-labs for Windows. By default, the application opens server port 3001 on all interfaces without requiring authentication. An attacker can exploit this weakness and gain unauthorized full backend access, potentially leading to the deletion or manipulation of all data within the workspace.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.