Loading HuntDB...

GHSA-rxmp-x6cw-79xv

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer token in single user mode. When decoded, the JWT reveals the password in plaintext. This improper storage of sensitive information poses significant security risks, as an attacker who gains access to the JWT can easily decode it and retrieve the password. The issue is fixed in version 1.0.3.

Related CVEs

Key Information

GHSA ID
GHSA-rxmp-x6cw-79xv
Published
October 29, 2024 3:32 PM
Last Modified
October 29, 2024 3:32 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 29, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.