timothycarambat
26 exploits
Active since Jan 2024
AnythingLLM < 1.0.0 - Authenticated Relative Path Traversal via Profile Picture API
CVSS 6.5
AnythingLLM < 1.0.0 - Authenticated Improper Access Control via Database Export Endpoint
CVSS 7.1
AnythingLLM < 1.0.0 - Authenticated Sensitive Data Exposure via Export Endpoint
CVSS 6.5
mintplex-labs/anything-llm <5c40419 - Info Disclosure
CVSS 8.3
AnythingLLM < 1.2.2 - Authenticated Path Traversal and Arbitrary File Manipulation via Document Uploads Manager
CVSS 7.2
mintplex-labs/anything-llm <1.3.1 - Path Traversal
CVSS 7.2
AnythingLLM < 2024-01-18 - Unauthenticated Denial of Service via File Export Endpoint
CVSS 7.5
AnythingLLM < 1.0.0 - Path Traversal via Logo Filename Manipulation
CVSS 9.9
AnythingLLM < 1.0.0 - Arbitrary File Read and Delete via Logo Filename Manipulation
CVSS 7.2
AnythingLLM < 1.0.0 - Unauthenticated User Deletion and Privilege Escalation via Malformed JSON Payload
CVSS 8.0
AnythingLLM < 1.0.0 - Unauthenticated Destructive VectorDB Actions via /api/v/ Endpoint
CVSS 9.4
mintplex-labs/anything-llm - JSON Injection
CVSS 5.3
AnythingLLM update-env Endpoint - Environment Variable Code Execution
CVSS 9.8
AnythingLLM < 1.0.0 - Stored Cross-Site Scripting via Unsanitized URL Embedding
CVSS 8.7
mintplex-labs/anything-llm - Privilege Escalation
CVSS 8.8
mintplex-labs/anything-llm - Privilege Escalation, SSRF
CVSS 8.8
AnythingLLM < 1.0.0 - Unauthenticated Database Manipulation via Import Endpoint
CVSS 9.1
AnythingLLM < 1.0.0 - Authenticated Denial of Service via Upload-Link Endpoint
CVSS 6.5
AnythingLLM < 1.0.0 - Path Traversal and Arbitrary File Write via Custom Logo Upload
CVSS 7.2
mintplex-labs/anything-llm <1.5.3 - Info Disclosure
CVSS 6.5
AnythingLLM < 1.0.0 - Denial of Service via Uncontrolled Username Size
CVSS 7.5
mintplexlabs/anything-llm < 1.3.1 - Denial of Service via Low Sample Rate Audio File Upload
CVSS 6.5
AnythingLLM Desktop < 1.6.5 - Unauthenticated Backend Access via Open Port
CVSS 9.8
mintplex-labs/anything-llm <1.2.2 - Path Traversal
CVSS 7.2
mintplex-labs/anything-llm <6dc3642 - DoS
CVSS 7.5