PT-2026-44551 · Unknown · Anything-Llm

·

CVE-2026-47713

·

Published

2026-05-28

·

Updated

2026-07-21

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions AnythingLLM versions prior to 1.13.0
Description An issue exists where a mobile device token created in single-user mode remains valid after migration to multi-user mode, even if the device record has userId set to null. The mobile authentication middleware continues to accept this stale token. Since no user is associated with the request, mobile handlers use unscoped data-access branches, returning workspaces and content without per-user filtering. This allows a pre-migration token to enumerate workspaces assigned to other users and retrieve thread metadata and chat content.
Recommendations Update to version 1.13.0.

Exploit

Fix

Improper Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47713
GHSA-H349-HP2V-8RHW

Affected Products

Anything-Llm