Medium severity6.5NVD Advisory· Published Feb 28, 2024· Updated Jun 17, 2026
CVE-2024-0550
CVE-2024-0550
Description
A user who is privileged already manager or admin can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files.
The attacker would have to have been granted privileged permissions to the system before executing this attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*range: <1.0.0
- (no CPE)
- mintplex-labs/mintplex-labs/anything-llmv5Range: unspecified
Patches
Vulnerability mechanics
References
2- github.com/mintplex-labs/anything-llm/commit/e1dcd5ded010b03abd6aa32d1bf0668a48e38e17nvdPatch
- huntr.com/bounties/c6afeb5e-f211-4b3d-aa4b-6bad734217a6nvdExploitIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.