Vulnerabilities > Mintplexlabs > Anythingllm Docker > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-03-20 CVE-2024-13060 Unspecified vulnerability in Mintplexlabs Anythingllm Docker
A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie.
network
low complexity
mintplexlabs
4.3