Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

CVE-2026-24477 (CVSS 9.1) exposes the Qdrant vector database API key in plaintext via an unauthenticated GET request to AnythingLLM’s /api/setup-complete endpoint, affecting all versions prior to 1.10.0. Confirmed on CISA KEV with active exploitation; a successful attacker gains full read/write access to the RAG knowledge base, enabling document exfiltration, embedding poisoning, and data destruction. Upgrade to AnythingLLM 1.10.0 immediately and rotate the Qdrant API key; restrict the endpoint at the WAF or reverse proxy layer pending patch deployment.

Author

Tech Jacks Solutions