CVE-2024-8251

MEDIUM

mintplex-labs/anything-llm <1.2.2 - Code Injection

Title source: llm
STIX 2.1

Description

A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint "/embed/:embedId/stream-chat" where user-provided JSON is directly taken to the Prisma library's where clause. An attacker can exploit this by providing a specially crafted JSON object, such as {"sessionId":{"not":"a"}}, causing Prisma to return all data from the table. This can lead to unauthorized access to all user queries in embedded chat mode.

Scores

CVSS v3 5.3
EPSS 0.0047
EPSS Percentile 64.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
mintplexlabs/anythingllm < 1.2.2
Published Mar 20, 2025
Tracked Since Feb 18, 2026