Loading HuntDB...

GHSA-953g-4rmq-23v8

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application fails to validate or format JSON data sent in an HTTP POST request to `/api/workspace/:workspace-slug/update`, allowing it to be executed as part of a database query without restrictions. This flaw enables users with a manager role to craft a request that includes nested write operations, effectively allowing them to create new Administrator accounts.

Related CVEs

Key Information

GHSA ID
GHSA-953g-4rmq-23v8
Published
May 20, 2024 3:31 PM
Last Modified
May 20, 2024 3:31 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 9, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.