Vulnerability CVE-2024-0763


Published: 2024-02-27

Description:
Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need access to the server at some privilege level since this endpoint is protected and requires authorization.

Type:

CWE-20

(Improper Input Validation)

 References:
https://huntr.com/bounties/25a2f487-5a9c-4c7f-a2d3-b0527db73ea5
https://github.com/mintplex-labs/anything-llm/commit/8a7324d0e77a15186e1ad5e5119fca4fb224c39c

Copyright 2026, cxsecurity.com

 

Back to Top