CVE-2024-13060

MEDIUM

AnythingLLM Docker <1.3.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie. This issue is present in versions prior to 1.3.1.

Scores

CVSS v3 4.3
EPSS 0.0042
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
mintplexlabs/anythingllm_docker < 1.3.1
Published Mar 20, 2025
Tracked Since Feb 18, 2026