PT-2025-52256 · Unknown · Anything-Llm
Zhihuang Liu
·
Published
2025-12-18
·
Updated
2025-12-20
·
CVE-2025-63390
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AnythingLLM version 1.8.5
Description
An authentication bypass allows unauthenticated remote attackers to enumerate and retrieve detailed information about all configured workspaces. The issue is due to missing authentication checks in the
/api/workspaces endpoint. Exposed data includes workspace identifiers (id, name, slug), AI model configurations (chatProvider, chatModel, agentProvider), system prompts (openAiPrompt), operational parameters (temperature, history length, similarity thresholds), vector search settings, chat modes, and timestamps.Recommendations
Apply authentication checks to the
/api/workspaces endpoint to prevent unauthorized access to workspace configuration details.Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anything-Llm