CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie. This issue is present in versions prio...Show more |
1Mintplexlabs 3Anythingllm Desktop Anythingllm DockerAnythingllm WebappJun 17, 2026 Jun 6, 2024 N/A· v4 9.6 CRITICAL· v3 N/A· v2 A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application. The vulnerability arises from the appli...Show more |