Skip to content

Known CVE

AnythingLLM - Information Disclosure

AnythingLLM suffers from an information disclosure vulnerability through the `/api/setup-complete` API endpoint. By accessing this endpoint, a remote and unauthenticated attacker can access sensitive configuration of the target AnythingLLM instance. This detection is included in the AI and LLM category.

CVE-2024-6842

High2024CVSS 7.5CWE-200

cve2024 · unauth · exposure · anything-llm · mintplex-labs · vuln · ai

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website