CVE-2026-72917

⚪ Do wiadomości

Błąd w AnythingLLM umożliwia przejęcie konta administratora przez wykorzystanie kodu odzyskiwania.

CVSS
5.9
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in server/utils/PasswordRecovery/index.js uses recoverAccount() to deduplicate the raw recoveryCodes values before trimming them, so one valid code submitted twice with different surrounding whitespace can satisfy the two-code check. Each normalized value can also match the same stored hash instead of consuming a distinct hash. An attacker who knows the target username and one recovery code can call POST /api/system/recover-account in multi-user mode, receive a password-reset token, and use POST /api/system/reset-password to take over the account, including an administrator account.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.9
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-08-10 22:17:10 UTC
Ostatnia modyfikacja (NVD)2026-09-18 20:09:01 UTC
Referencje