Unauthenticated Account Recovery Vulnerability in AnythingLLM by Mintplex Labs
CVE-2026-72917
5.9MEDIUM
What is CVE-2026-72917?
The vulnerability found in AnythingLLM allows an attacker to exploit the unauthenticated account recovery feature by manipulating the recovery process. Due to improper handling of whitespace in recovery codes, an attacker who knows the username and a valid recovery code can exploit this flaw. By submitting a recovery code with trailing or leading whitespace, the attacker can bypass the usual checks, obtain a password-reset token, and subsequently take over the targeted account, including administrative privileges. This flaw highlights a significant security oversight in how recovery codes are processed and should prompt immediate remediation to ensure user accounts remain secure.
Affected Version(s)
anything-llm Affected versions >= 1.0.0, <= 1.15.0
