CVE-2024-7783

HIGH

Mintplexlabs Anythingllm < 1.2.1 - Cleartext Storage

Title source: rule
STIX 2.1

Description

mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the password in plaintext. This improper storage of sensitive information poses significant security risks, as an attacker who gains access to the JWT can easily decode it and retrieve the password. The issue is fixed in version 1.0.3.

Scores

CVSS v3 7.5
EPSS 0.0013
EPSS Percentile 32.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
mintplexlabs/anythingllm < 1.2.1
Published Oct 29, 2024
Tracked Since Feb 18, 2026