Description
AnythingLLM is a full-stack app allowing you to build a private ChatGPT using commercial or open-source LLMs and vectorDB solutions, both locally and remotely, for intelligent document chat.
Acunetix determined that it was possible to access AnythingLLM API without authentication.
Remediation
Enable authentication for AnythingLLM
References
Related Vulnerabilities
WordPress Plugin WP-RecentComments Information Disclosure (2.2.7)
Unrestricted access to Prometheus Metrics
Overly long session timeout in servlet configuration
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6335)
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-34466)