CVE Explorer
CVE-2026-47713
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, an approved mobile device token created in single-user mode can survive single-user -> multi-user migration even when the device record has userId = null. In multi-user mode, that stale token is still accepted by the mobile authentication middleware. Because no user is attached to the request, downstream mobile handlers fall back to unscoped data-access bra
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:beb66db586a800c7a2d419472c127aa33193fa530533d5ee656d531f226256a3 · sha256:57c0a8e8f0f2936b… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:beb66db586a800c7a2d419472c127aa33193fa530533d5ee656d531f226256a3 · sha256:57c0a8e8f0f2936b… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"anything-llm","vendor":"Mintplex-Labs","versions":[{"status":"affected","version":"< 1.13.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:beb66db586a800c7a2d419472c127aa33193fa530533d5ee656d531f226256a3 · sha256:57c0a8e8f0f2936b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":2,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:beb66db586a800c7a2d419472c127aa33193fa530533d5ee656d531f226256a3 · sha256:57c0a8e8f0f2936b… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:beb66db586a800c7a2d419472c127aa33193fa530533d5ee656d531f226256a3 · sha256:57c0a8e8f0f2936b… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:beb66db586a800c7a2d419472c127aa33193fa530533d5ee656d531f226256a3 · sha256:57c0a8e8f0f2936b… · /containers/cna/problemTypes/1/descriptions/0
Source references
3 source assertions{"name":"https://github.com/Mintplex-Labs/anything-llm/commit/9d714f95c124b61df00b840e36f623a2eb7e7eb4","tags":["x_refsource_MISC"],"url":"https://github.com/Mintplex-Labs/anything-llm/commit/9d714f95c124b61df00b840e36f623a2eb7e7eb4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:beb66db586a800c7a2d419472c127aa33193fa530533d5ee656d531f226256a3 · sha256:57c0a8e8f0f2936b… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-h349-hp2v-8rhw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:beb66db586a800c7a2d419472c127aa33193fa530533d5ee656d531f226256a3 · sha256:57c0a8e8f0f2936b… · /containers/adp/0/references/0
{"name":"https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-h349-hp2v-8rhw","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-h349-hp2v-8rhw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:beb66db586a800c7a2d419472c127aa33193fa530533d5ee656d531f226256a3 · sha256:57c0a8e8f0f2936b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.