Loading
Generated remediation guidance and an executive summary. No account required.
A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie. This issue is present in versions prior to 1.3.1.
Cite this page
CVE-2024-13060. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2024-13060
Use CWE-862, Mintplexlabs vendor hub and Anythingllm Docker product page to widen CVE-2024-13060 into its surrounding weakness, vendor, and product context.
Additional editorial context is available in Container Security Mastery: A Guide to Scanning Images for Known CVEs.