CVE-2024-0763

HIGH

Path Traversal

Title source: llm
STIX 2.1

Description

Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need access to the server at some privilege level since this endpoint is protected and requires authorization.

Scores

CVSS v3 8.1
EPSS 0.0069
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
mintplexlabs/anythingllm < 1.0.0
Published Feb 27, 2024
Tracked Since Feb 18, 2026