Description

AnythingLLM is a full-stack app allowing you to build a private ChatGPT using commercial or open-source LLMs and vectorDB solutions, both locally and remotely, for intelligent document chat.

Acunetix determined that it was possible to access AnythingLLM API without authentication.

Remediation

Enable authentication for AnythingLLM

References

Related Vulnerabilities