CVE-2026-24477 | mintplex-labs anything-llm up to 1.9.x /api/setup-complete insertion of sensitive information into sent data (GHSA-gm94-qc2p-xcwf)
A vulnerability, which was classified as problematic, has been found in mintplex-labs anything-llm up to 1.9.x. Affected by this vulnerability is an unknown functionality of the file /api/setup-complete. Performing a manipulation results in insertion of sensitive information into sent data.
This vulnerability was named CVE-2026-24477. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.