PT-2026-39221 · Unknown · Anything-Llm
C4Tzzz
·
Published
2026-05-08
·
Updated
2026-05-18
·
CVE-2026-42456
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AnythingLLM versions prior to 1.12.1
Description
An insecure direct object reference (IDOR) exists in the text-to-speech endpoint. The endpoint "/api/workspace/:slug/tts/:chatId" validates workspace membership but fails to enforce ownership of the targeted chat row. This allows an authenticated user to access another user's private assistant response in audio form if the
chatId is known or guessed.Recommendations
Update to version 1.12.1.
Exploit
Fix
Information Disclosure
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anything-Llm