Username Enumeration Vulnerability in AnythingLLM Application by Mintplex Labs
CVE-2026-21484
What is CVE-2026-21484?
The AnythingLLM application, a tool that provides context references for large language models, contains a vulnerability in its password recovery functionality. This flaw allows attackers to determine whether a specific username exists by interpreting different error messages returned based on username validity, potentially compromising account security. This issue was addressed in a commit that harmonized the error messages returned by the password recovery endpoint, thereby mitigating the risk of username enumeration attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
anything-llm < e287fab56089cf8fcea9ba579a3ecdeca0daa313
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
