PT-2026-25397 · Unknown · Anything-Llm
U-Ktdi
·
Published
2026-03-13
·
Updated
2026-03-16
·
CVE-2026-32717
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
AnythingLLM versions 1.11.1 and earlier
Description
AnythingLLM is an application designed to provide context for Large Language Models (LLMs). In multi-user mode, the application fails to block suspended users accessing the system through browser extension API keys, despite blocking them through standard JWT-backed sessions. A suspended user with a valid
brx-... browser extension API key can continue to access browser extension endpoints, read workspace metadata, and perform upload or embed operations. The vulnerable API key path allows continued access even after normal authentication is denied.Recommendations
Versions prior to 1.11.1 should be updated. Ensure that browser extension API keys are invalidated or access is revoked upon user suspension.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anything-Llm