Description
AnythingLLM is a full-stack app allowing you to build a private ChatGPT using commercial or open-source LLMs and vectorDB solutions, both locally and remotely, for intelligent document chat.
Acunetix determined that it was possible to access AnythingLLM API without authentication.
Remediation
Enable authentication for AnythingLLM
References
Related Vulnerabilities
GraphQL Circular-Query via Introspection Allowed: Potential DoS Vulnerability
WordPress Plugin WP-Live Chat by 3CX Information Disclosure (8.0.28)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-6727)
Go web application binary disclosure
Undertow Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-1745)