Authentication Bypass in AnythingLLM Desktop Application by Mintplex Labs
CVE-2026-32617
What is CVE-2026-32617?
The AnythingLLM application, designed to facilitate interactions between users and language models, has a significant vulnerability present in versions 1.11.1 and earlier. By default, installations without configured passwords or API keys expose all HTTP endpoints and the agent WebSocket, lacking necessary authentication measures. Additionally, the server's CORS policy permits any origin, further compromising security. While AnythingLLM Desktop defaults to binding to the loopback address (127.0.0.1), modern browsers implement Private Network Access, effectively blocking external public websites from accessing local services. This limitation means that exploitation is confined to users within the same local network, raising concerns for network security in shared environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
anything-llm <= 1.11.1
