PT-2025-52256 · Unknown · Anything-Llm

Zhihuang Liu

·

Published

2025-12-18

·

Updated

2025-12-20

·

CVE-2025-63390

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions AnythingLLM version 1.8.5
Description An authentication bypass allows unauthenticated remote attackers to enumerate and retrieve detailed information about all configured workspaces. The issue is due to missing authentication checks in the /api/workspaces endpoint. Exposed data includes workspace identifiers (id, name, slug), AI model configurations (chatProvider, chatModel, agentProvider), system prompts (openAiPrompt), operational parameters (temperature, history length, similarity thresholds), vector search settings, chat modes, and timestamps.
Recommendations Apply authentication checks to the /api/workspaces endpoint to prevent unauthorized access to workspace configuration details.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-63390

Affected Products

Anything-Llm