Loading HuntDB...

GHSA-jq5m-3v7c-39qm

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipulating the 'logo_filename' parameter in the 'system-preferences' API endpoint, an attacker can construct requests to read sensitive files or the application's '.env' file, and even delete files by setting the 'logo_filename' to the path of the target file and invoking the 'remove-logo' API endpoint. This vulnerability is due to the lack of proper sanitization of user-supplied input.

Related CVEs

Key Information

GHSA ID
GHSA-jq5m-3v7c-39qm
Published
April 16, 2024 12:30 AM
Last Modified
April 16, 2024 12:30 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 9, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.