VYPR
High severity7.5NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026

CVE-2024-6842

CVE-2024-6842

Description

In version 1.5.5 of mintplex-labs/anything-llm, the /setup-complete API endpoint allows unauthorized users to access sensitive system settings. The data returned by the currentSettings function includes sensitive information such as API keys for search engines, which can be exploited by attackers to steal these keys and cause loss of user assets.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:mintplexlabs:anythingllm:1.5.5:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mintplexlabs:anythingllm:1.5.5:*:*:*:*:*:*:*
    • (no CPE)range: <1.5.5
  • mintplex-labs/mintplex-labs/anything-llmv5
    Range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.