mintplex-labs/anything-llm
cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*
- git 296f041
A path traversal vulnerability has been identified in the normalizePath function of Mintplex Labs' Anything-LLM, specifically in version git 296f041. This vulnerability allows for arbitrary file read and write operations within the application's storage directory. The issue arises because the normalizePath function fails to properly sanitize certain file path inputs, enabling malicious users to traverse directories and manipulate files. Exploiting this vulnerability can lead to unauthorized privilege escalation, particularly from a manager to an admin role.
The vulnerability allows for arbitrary file read, write, and deletion operations within the application's storage directory. This could disrupt normal application functionality, especially if critical database files are deleted. Additionally, the vulnerability can be exploited to escalate privileges, as demonstrated by overwriting a database file to gain admin rights.
The vulnerability can be reproduced by uploading a profile picture, which is then used to facilitate the exploitation. After uploading the picture, the Anything-LLM database file is moved to a publicly accessible folder. Once the database file is downloaded, it can be modified to grant admin privileges to a user account. The modified database file is then uploaded back to the application, effectively transferring the admin rights. This exploitation process takes advantage of the application's file handling endpoints, demonstrating the path traversal vulnerability and its consequences.
Users are advised to update to version 1.2.2, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.