CVE-2024-0404 is a critical mass assignment vulnerability in the mintplex-labs/anything-llm repository, specifically affecting the /api/invite/:code endpoint. An attacker can exploit this by modifying HTTP requests during account creation via an invitation link, adding an "admin" role property due to a lack of proper property validation. This allows for unauthorized creation of high-privileged accounts, leading to complete administrative access. With a CVSS score of 9.1 (Critical), the vulnerability is easily exploitable over the network with no user interaction required, enabling full compromise of confidentiality and integrity. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0CPE matchmatch criteria | cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.