๐Ÿ” CVE Alert

CVE-2026-24477

UNKNOWN 0.0

AnythingLLM has key leak in `systemSettings.js`

CVSS Score
0.0
EPSS Score
10.8%
EPSS Percentile
93th

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. If AnythingLLM prior to version 1.10.0 is configured to use Qdrant as the vector database with an API key, this QdrantApiKey could be exposed in plain text to unauthenticated users via the `/api/setup-complete` endpoint. Leakage of QdrantApiKey allows an unauthenticated attacker full read/write access to the Qdrant vector database instance used by AnythingLLM. Since Qdrant often stores the core knowledge base for RAG in AnythingLLM, this can lead to complete compromise of the semantic search / retrieval functionality and indirect leakage of confidential uploaded documents. Version 1.10.0 patches the issue.

CWE CWE-201
Vendor mintplex-labs
Product anything-llm
Published Jan 26, 2026
Last Updated Apr 3, 2026
Stay Ahead of the Next One

Get instant alerts for mintplex-labs anything-llm

Be the first to know when new unknown vulnerabilities affecting mintplex-labs anything-llm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Mintplex-Labs / anything-llm
< 1.10.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-gm94-qc2p-xcwf