PT-2026-25397 · Unknown · Anything-Llm

U-Ktdi

·

Publicado

2026-03-13

·

Atualizado

2026-03-16

·

CVE-2026-32717

CVSS v2.0

3.3

Baixa

VetorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions AnythingLLM versions 1.11.1 and earlier
Description AnythingLLM is an application designed to provide context for Large Language Models (LLMs). In multi-user mode, the application fails to block suspended users accessing the system through browser extension API keys, despite blocking them through standard JWT-backed sessions. A suspended user with a valid brx-... browser extension API key can continue to access browser extension endpoints, read workspace metadata, and perform upload or embed operations. The vulnerable API key path allows continued access even after normal authentication is denied.
Recommendations Versions prior to 1.11.1 should be updated. Ensure that browser extension API keys are invalidated or access is revoked upon user suspension.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-04253
CVE-2026-32717
GHSA-7754-8JCC-2RG3

Produtos afetados

Anything-Llm