VYPR

Anythingllm Desktop

by Mintplex Labs

Source repositories

CVEs (2)

  • CVE-2024-8196CriMar 20, 2025
    risk 0.00cvss 9.8epss 0.01

    In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as deleting all data…

  • CVE-2024-3166CriJun 6, 2024
    risk 0.00cvss 9.6epss 0.01

    A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application. The vulnerability arises from the application's feature to fetch and embed content from websites…