CVE-2024-0440 CRITICAL

CVE-2024-0440: SSRF - file:// unsanitized access to underlying host files

Vendor Mintplex-Labs
Product mintplex-labs/anything-llm
Weakness CWE-918 · SSRF
Published February 25, 2024
Last update August 28, 2024

CVSS base score

9.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host files and other relatively stored files.

Key dates

02Disclosure timeline

February 25, 2024 CVE published
August 28, 2024 Record updated