AnythingLLM unauthenticated /system/data-import access control bypass (CVE-2024-3279) - ATR-2026-01974 (d730bfd9-bd70-5336-9de5-2894688650d8)
CVE-2024-3279: improper access control on the mintplex-labs/anything-llm POST /system/data-import endpoint (<1.0.0). An anonymous, unauthenticated attacker uploads their own database file via multipart formData, deleting or spoofing the existing anythingllm.db SQLite database to serve malicious data or harvest user info. This rule keys on the data-import endpoint path combined with the database-file import sink (anythingllm.db / data-import upload).