{"id":"CVE-2024-10109","summary":"Incorrect Authorization in mintplex-labs/anything-llm","details":"A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint \"/api/system/custom-models\". This access enables them to modify the model's API key and base path, leading to potential API key leakage and denial of service on chats.","modified":"2026-07-15T01:49:13.084578885Z","published":"2025-03-20T10:09:27.423Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10109.json","unresolved_ranges":[{"extracted_events":[{"fixed":"1.3.1"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"@huntr_ai","cwe_ids":["CWE-863"]},"references":[{"type":"WEB","url":"https://huntr.com/bounties/ad3c9e76-679d-4775-b203-96947ff73551"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10109.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-10109"},{"type":"FIX","url":"https://github.com/mintplex-labs/anything-llm/commit/8d302c3f670c582b09d47e96132c248101447a11"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mintplex-labs/anything-llm","events":[{"introduced":"0"},{"fixed":"8d302c3f670c582b09d47e96132c248101447a11"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v1.3.0","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.1.1","v1.1.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10109.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H"}]}