Timothy Carambat
37 exploits
Active since Sep 2023
AnythingLLM < 1.12.1 - Stored DOM XSS in Chart Caption Renderer
CVSS 5.4
Path Traversal in mintplex-labs/anything-llm
CVSS 7.2
AnythingLLM has SQL Injection in Built-in SQL Agent Plugin via Unsanitized table_name Parameter
CVSS 8.8
AnythingLLM Manager Privilege Bypass Allows Access to Admin-Only System Preferences
CVSS 3.8
AnythingLLM access control bypass: suspended users can continue using Browser Extension API keys
CVSS 2.7
AnythingLLM has a Zip Slip Path Traversal and Code Execution via Community Hub Plugin Import
CVSS 4.2
AnythingLLM Desktop <=1.11.1 - XSS to RCE
CVSS 9.6
mintplex-labs/anything-llm <0.0.1 - Path Traversal
CVSS 9.8
mintplex-labs/anything-llm <0.0.1 - Auth Bypass
CVSS 7.5
mintplex-labs/anything-llm <0.0.1 - SQL Injection
CVSS 8.8
Mintplexlabs Anythingllm < 0.1.0 - Improper Input Validation
CVSS 9.1
Mintplexlabs Anythingllm < 0.1.0 - Improper Access Control
CVSS 8.8
Mintplex-Labs Anything-LLM - Privilege Escalation
CVSS 9.1
Mintplexlabs Anythingllm - XSS
CVSS 5.4
Mintplexlabs Anythingllm < 1.0.0 - Information Disclosure
CVSS 5.9
Mintplexlabs Anythingllm < 1.0.0 - Improper Privilege Management
CVSS 8.8
Mintplexlabs AnythingLLM - Server-Side Request Forgery
CVSS 6.5
AnythingLLC - Info Disclosure
CVSS 7.5
mintplex-labs/anything-llm - Path Traversal
CVSS 8.1
AnythingLLM - SSRF
CVSS 7.5
Path Traversal
CVSS 8.1
Unspecified - Privilege Escalation
CVSS 7.2
mintplex-labs/anything-llm - Privilege Escalation
CVSS 6.5
AnythingLLM Docker <1.3.1 - Info Disclosure
CVSS 4.3
mintplex-labs/anything-llm - Privilege Escalation
CVSS 7.2