CVE-2024-0549

HIGH
Published Apr 16, 2024 Modified Jul 9, 2025 CWE-23

Description

mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete files and folders within the filesystem, including critical database files such as 'anythingllm.db'. The vulnerability stems from insufficient input validation and normalization in the handling of file and folder deletion requests. Successful exploitation results in the compromise of data integrity and availability.

Is your site exposed to CVE-2024-0549?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

8.1
HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Weakness Type (CWE)

CWE-23 CWE-23

Affected Products

Vendor Product
mintplexlabs anythingllm

References

Frequently Asked Questions

What is CVE-2024-0549? +
mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete files and folders within the filesystem, including critical database files such as 'anythingllm.db'. The vulnerability stems from insufficient input validation and normalization in the handling of file and folder deletion requests. Successful exploitation results in the compromise of data integrity and availability. It has a CVSS v3.1 base score of 8.1 (HIGH).
How severe is CVE-2024-0549? +
CVE-2024-0549 has a CVSS v3.1 score of 8.1 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-0549? +
CVE-2024-0549 affects products from mintplexlabs, specifically: anythingllm. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-0549? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-0549 — free, no signup required.