PT-2026-39221 · Unknown · Anything-Llm
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AnythingLLM versions prior to 1.12.1
Description
An insecure direct object reference (IDOR) exists in the text-to-speech endpoint. The endpoint "/api/workspace/:slug/tts/:chatId" validates workspace membership but fails to enforce ownership of the targeted chat row. This allows an authenticated user to access another user's private assistant response in audio form if the
chatId is known or guessed.Recommendations
Update to version 1.12.1.
Exploit
Fix
IDOR
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anything-Llm