mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifically, the server can be shut down by sending an invalid upload request. An attacker with the ability to upload documents can exploit this vulnerability to cause a DOS condition by manipulating the upload request.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Fri, 20 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Mintplexlabs Mintplexlabs anythingllm | |
| CPEs | cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* | |
| Vendors & Products | Mintplexlabs Mintplexlabs anythingllm | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-06T18:40:53.604Z
Updated: 2024-08-01T20:05:07.642Z
Reserved: 2024-04-01T19:03:02.962Z
Link: CVE-2024-3153
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-01T20:05:07.642Z
 NVD
                        NVD
                    Status : Modified
Published: 2024-06-06T19:16:00.600
Modified: 2024-11-21T09:29:00.963
Link: CVE-2024-3153
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow