CVE detail
CVE-2024-0439 — CVE-2024-0439
Published 2024-02-26 · Modified 2026-06-17 · Vendor mintplexlabs · Product anythingllm · Source nvd
HIGH
severity
CVSS-derived band
0.0064
EPSS probability
exploitation probability, 30d
47.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to modify these settings. They can use their token to still modify those settings though through a standard HTTP request
While this is not a critical vulnerability, it does indeed need to be patched to enforce the expected permission level.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References