Description
A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is running in 'just me' mode with a password. An attacker can exploit this vulnerability by making a request to the endpoint using the [validatedRequest] middleware with a specially crafted 'Authorization:' header. This vulnerability leads to uncontrolled resource consumption, causing a DoS condition.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/619e13bd-b723-4727-9ccb-5099d698432e
Scores
CVSS v3
7.5
EPSS
0.0014
EPSS Percentile
34.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (1)
mintplexlabs/anythingllm
< 1.0.0
Published
Apr 10, 2024
Tracked Since
Feb 18, 2026