High severity7.2NVD Advisory· Published May 20, 2024· Updated Jun 17, 2026
CVE-2024-4287
CVE-2024-4287
Description
In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application fails to validate or format JSON data sent in an HTTP POST request to /api/workspace/:workspace-slug/update, allowing it to be executed as part of a database query without restrictions. This flaw enables users with a manager role to craft a request that includes nested write operations, effectively allowing them to create new Administrator accounts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*range: <1.0.0
- (no CPE)
- mintplex-labs/mintplex-labs/anything-llmv5Range: unspecified
Patches
Vulnerability mechanics
References
2- github.com/mintplex-labs/anything-llm/commit/94b58249a37a21b1c08deaa2d1edfdecbb6deb18nvdPatch
- huntr.com/bounties/34491fb7-5133-4e80-8782-74124350bbdbnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.