Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

mintplex-labs — Vulnerabilities & Security Advisories 75

Browse all 75 CVE security advisories affecting mintplex-labs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Mintplex Labs operates as a software development entity, primarily known for creating blockchain-based applications and smart contract solutions. An analysis of its public vulnerability record reveals 69 assigned CVEs, indicating a significant historical exposure to security flaws. The most prevalent vulnerability classes associated with the organization’s codebase include remote code execution (RCE), cross-site scripting (XSS), and privilege escalation issues. These defects often stem from inadequate input validation and improper access control mechanisms within their web interfaces and backend services. While specific major incidents involving data breaches are not widely documented in public threat intelligence feeds, the high volume of CVEs suggests systemic weaknesses in their software development lifecycle. This pattern highlights the critical need for rigorous static and dynamic analysis in blockchain-related projects to mitigate risks associated with complex smart contract interactions and standard web application vulnerabilities.

CVE IDTitleCVSSSeverityPublished
CVE-2024-0551 Download and export of file via default user role — mintplex-labs/anything-llmCWE-284 7.1 -2024-02-27
CVE-2024-0759 Collection of internally resolving IPs — mintplex-labs/anything-llmCWE-918 9.3 -2024-02-27
CVE-2024-0439 User can manually send request at manager permission to modify system configurations — mintplex-labs/anything-llmCWE-269 4.3 -2024-02-25
CVE-2024-0440 SSRF - file:// unsanitized access to underlying host files — mintplex-labs/anything-llmCWE-918 6.5 -2024-02-25
CVE-2024-0435 User can submit message to self-XSS — mintplex-labs/anything-llmCWE-79 5.4 -2024-02-25
CVE-2024-0798 Privilege Escalation in mintplex-labs/anything-llm — mintplex-labs/anything-llmCWE-272 4.9 -2024-02-25
CVE-2024-0436 Prevent timing attack for single-user password check — mintplex-labs/anything-llmCWE-203 6.7 -2024-02-25
CVE-2024-0455 SSRF on AWS deployed instances of AnythingLLM via /metadata — mintplex-labs/anything-llmCWE-918 8.8 -2024-02-25
CVE-2024-0879 Authentication bypass in vector-admin domain restriction — vector-adminCWE-287 6.5 Medium2024-01-25
CVE-2024-22422 Unauthenticated Denial of Service (DOS) attack in AnythingLLM — anything-llmCWE-754 7.5 High2024-01-19
CVE-2023-5833 Improper Access Control in mintplex-labs/anything-llm — mintplex-labs/anything-llmCWE-284 9.1 -2023-10-30
CVE-2023-5832 Improper Input Validation in mintplex-labs/anything-llm — mintplex-labs/anything-llmCWE-20 9.8 -2023-10-30
CVE-2023-4899 SQL Injection in mintplex-labs/anything-llm — mintplex-labs/anything-llmCWE-89 9.8 -2023-09-11
CVE-2023-4898 Authentication Bypass by Primary Weakness in mintplex-labs/anything-llm — mintplex-labs/anything-llmCWE-305 9.8 -2023-09-11
CVE-2023-4897 Relative Path Traversal in mintplex-labs/anything-llm — mintplex-labs/anything-llmCWE-23 9.1 -2023-09-11

This page lists every published CVE security advisory associated with mintplex-labs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.