CVE-2024-13060

MEDIUM

AnythingLLM Docker <1.3.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie. This issue is present in versions prior to 1.3.1.

Scores

CVSS v3 4.3
EPSS 0.0019
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
mintplexlabs/anythingllm_docker < 1.3.1
Published Mar 20, 2025
Tracked Since Feb 18, 2026