PT-2026-44551 · Unknown · Anything-Llm
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AnythingLLM versions prior to 1.13.0
Description
An issue exists where a mobile device token created in single-user mode remains valid after migration to multi-user mode, even if the device record has
userId set to null. The mobile authentication middleware continues to accept this stale token. Since no user is associated with the request, mobile handlers use unscoped data-access branches, returning workspaces and content without per-user filtering. This allows a pre-migration token to enumerate workspaces assigned to other users and retrieve thread metadata and chat content.Recommendations
Update to version 1.13.0.
Exploit
Fix
Improper Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anything-Llm