Skip to content

Hide Navigation Hide TOC

AnythingLLM Logo Endpoint Path Traversal File Read/Delete (CVE-2024-3025) - ATR-2026-01973 (ab22439c-7105-5522-a95a-7ad5a33994a3)

Detects CVE-2024-3025 (CWE-23, CVSS CRITICAL): mintplex-labs/anything-llm before 1.0.0 fails to validate the user-supplied logo filename on the /api/system/upload-logo and /api/system/logo endpoints. An authenticated attacker passes path-traversal sequences (../../../) in the logo filename to read or delete arbitrary files outside the assets directory, with the SQLite database storage/anythingllm.db as a high-value target. The fix added a normalizePath() guard. This rule keys on the specific logo endpoint paths combined with ../ traversal (raw or %2e%2e%2f-encoded) into storage/anythingllm.db.

Cluster A Galaxy A Cluster B Galaxy B Level
Exploit Public-Facing Application (47d73872-5336-44f7-81e3-d30bc7e039dd) MITRE ATLAS Attack Pattern AnythingLLM Logo Endpoint Path Traversal File Read/Delete (CVE-2024-3025) - ATR-2026-01973 (ab22439c-7105-5522-a95a-7ad5a33994a3) Agent Threat Rules 1
Exploit Public-Facing Application - T1190 (3f886f2a-874f-4333-b794-aa6075009b1c) Attack Pattern AnythingLLM Logo Endpoint Path Traversal File Read/Delete (CVE-2024-3025) - ATR-2026-01973 (ab22439c-7105-5522-a95a-7ad5a33994a3) Agent Threat Rules 1