CVE-2024-3166
AnythingLLM Cross-Site Scripting Leading to Remote Code Execution
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A cross-site scripting vulnerability exists in AnythingLLM, allowing arbitrary JavaScript execution when embedding external web content. In the desktop version, this could escalate to remote code execution, posing a risk to users and systems interacting with the application's content integration features. This is a cri