Mintplex-Labs AnythingLLM是Mintplex-Labs组织开源的一款一体化的 RAG(检索增强生成)应用程序。 Mintplex-Labs AnythingLLM 1.0.0版本至1.15.0版本存在安全漏洞,该漏洞源于其未认证的账户恢复流程在server/utils/PasswordRecovery/index.js中对recoveryCodes值去重时未先修剪空白,导致同一有效恢复代码可重复满足两代码校验,攻击者可通过POST /api/system/recover-accou
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mintplex-Labs | anything-llm | Affected versions >= 1.0.0, <= 1.15.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mintplex-Labs | anything-llm | Affected versions >= 1.0.0, <= 1.15.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet