Medium severity6.5NVD Advisory· Published Jun 6, 2024· Updated Jun 17, 2026
CVE-2024-3153
CVE-2024-3153
Description
mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifically, the server can be shut down by sending an invalid upload request. An attacker with the ability to upload documents can exploit this vulnerability to cause a DOS condition by manipulating the upload request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*range: <1.0.0
- (no CPE)
- mintplex-labs/mintplex-labs/anything-llmv5Range: unspecified
Patches
Vulnerability mechanics
References
2- github.com/mintplex-labs/anything-llm/commit/b8d37d9f43af2facab4c51146a46229a58cb53d9nvdPatch
- huntr.com/bounties/7bb08e7b-fd99-411e-99bc-07f81f474635nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.