Anything Llm
Vendor:
First CVE: Sep 11, 2023 · Active for 2 years
69
Total CVEs
More Total CVEs than 49% of tracked products
17.3
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Anything Llm over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2023
2 years ago
Most Recent CVE
May 28, 2026
58 days ago
CVE Severity & Scoring
Anything Llm69 CVEs
30%
54%
12%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.4%)
Network68 (98.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low64 (92.8%)
High5 (7.2%)
Unknown0 (0.0%)
User Interaction
None61 (88.4%)
Unknown0 (0.0%)
Required8 (11.6%)
Privileges Required
Low29 (42.0%)
High15 (21.7%)
None25 (36.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (69 CVEs).
69 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6842HIGH In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentS | Mar 20, 2025 | 7.5 | 51 | NO | YES |
CVE-2026-48116HIGH AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill | May 28, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-24477HIGH AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. If AnythingLLM prior to version 1.10.0 is configured to | Jan 27, 2026 | 7.5 | 36 | NO | YES |
CVE-2024-13059HIGH A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library. This vulnerabi | Feb 10, 2025 | 7.2 | 36 | NO | NO |
CVE-2026-32626CRITICAL AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a St | Mar 13, 2026 | 9.6 | 34 | NO | NO |
CVE-2026-32628HIGH AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL injection vulnerability in | Mar 13, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-21484MEDIUM AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313 | Jan 3, 2026 | 5.3 | 30 | NO | YES |
CVE-2023-4897CRITICAL Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1. | Sep 11, 2023 | 9.8 | 29 | NO | NO |
CVE-2026-5627HIGH A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `AgentFlows` component. The vulnerability arises from improper ha | Apr 7, 2026 | 7.2 | 27 | NO | NO |
CVE-2024-3025CRITICAL mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input in the logo filename functionality. Attackers can exploit t | Apr 10, 2024 | 9.9 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (69 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
4.3% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (69 CVEs).
Media Mentions
Signals from CVEs in this product scope (69 CVEs).
Top CNAs Publishing CVEs For Anything Llm
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.8.5 | 1 | 5.3 | 0.5% | 0 | 0 |
| 1.5.5 | 1 | 7.5 | 30.8% | 0 | 1 |