mintplex-labs/anything-llm
cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*
- git 6dc3642
A denial-of-service vulnerability has been identified in Mintplex Labs Anything-LLM, specifically in the API for the embeddable chat feature. This issue, present in version git 6dc3642, allows an attacker to cause a server crash by sending a malformed JSON payload to the API endpoint, leading to an uncaught exception. The vulnerability is fixed in version 1.2.2.
Exploitation of this vulnerability causes a server crash, disrupting service by terminating the server process handling the chat API.
Users can upgrade to version 1.2.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.