CVE Feed

    Dashboard / CVE / CVE-2024-8196

    CVE-2024-8196

    In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as deleting all data from the workspace.

    Published:Mar 20, 2025
    Last Modified:Jul 15, 2025
    EPS:Mar 20, 2025
    EPSS Score:0.00208
    CVSS Score:9.8

    Affected Products

    Vendor
    Microsoft
    Product
    Windows
    Vendor
    Mintplexlabs
    Product
    Anythingllm Desktop

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High