{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T07:33:13.870","vulnerabilities":[{"cve":{"id":"CVE-2024-8249","sourceIdentifier":"security@huntr.dev","published":"2025-03-20T10:15:41.860","lastModified":"2026-06-17T08:22:12.067","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the API for the embeddable chat functionality. An attacker can exploit this vulnerability by sending a malformed JSON payload to the API endpoint, causing a server crash due to an uncaught exception. This issue is fixed in version 1.2.2."},{"lang":"es","value":"La versión git 6dc3642 de mintplex-labs/anything-llm contiene una vulnerabilidad de denegación de servicio (DoS) no autenticada en la API para la funcionalidad de chat integrable. Un atacante puede explotar esta vulnerabilidad enviando una carga JSON malformada al endpoint de la API, lo que provoca un fallo del servidor debido a una excepción no detectada. Este problema se solucionó en la versión 1.2.2."}],"affected":[{"source":"security@huntr.dev","affectedData":[{"vendor":"mintplex-labs","product":"mintplex-labs/anything-llm","versions":[{"version":"unspecified","lessThan":"1.2.2","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-20T17:53:22.627107Z","id":"CVE-2024-8249","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-248"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*","versionEndExcluding":"1.2.2","matchCriteriaId":"49CA730F-D0B7-4FBA-B8ED-A524C40A075D"}]}]}],"references":[{"url":"https://github.com/mintplex-labs/anything-llm/commit/548da9ade30368289c5beaf0a8ee2ed2b5c1d81c","source":"security@huntr.dev","tags":["Patch"]},{"url":"https://huntr.com/bounties/2fb0c93f-5bc1-4212-bdca-292db7c6951f","source":"security@huntr.dev","tags":["Exploit","Third Party Advisory"]}]}}]}