← Back

CVE-2024-8248

nvd nist
Published: Mar 20, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: security@huntr.dev (Secondary)

Description

A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file read and write in the storage directory. This can result in privilege escalation from manager to admin. The issue is fixed in version 1.2.2.

Affected (1)

1 product
Anythingllm
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.2.2

Timeline

No history available yet.