Unauthenticated Account Recovery Vulnerability in AnythingLLM by Mintplex Labs
CVE-2026-72917

5.9MEDIUM

Key Information:

Vendor
CVE Published:
10 August 2026

What is CVE-2026-72917?

The vulnerability found in AnythingLLM allows an attacker to exploit the unauthenticated account recovery feature by manipulating the recovery process. Due to improper handling of whitespace in recovery codes, an attacker who knows the username and a valid recovery code can exploit this flaw. By submitting a recovery code with trailing or leading whitespace, the attacker can bypass the usual checks, obtain a password-reset token, and subsequently take over the targeted account, including administrative privileges. This flaw highlights a significant security oversight in how recovery codes are processed and should prompt immediate remediation to ensure user accounts remain secure.

Affected Version(s)

anything-llm Affected versions >= 1.0.0, <= 1.15.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.