AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery endpoint returns different error messages depending on whether a username exists, so enabling username enumeration. Commit e287fab56089cf8fcea9ba579a3ecdeca0daa313 fixes this issue.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 03 Jan 2026 01:45:00 +0000

Type Values Removed Values Added
Description AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery endpoint returns different error messages depending on whether a username exists, so enabling username enumeration. Commit e287fab56089cf8fcea9ba579a3ecdeca0daa313 fixes this issue.
Title AnythingLLM Vulnerable to Username Enumeration w/ Password Recovery
Weaknesses CWE-203
CWE-204
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-03T01:21:39.386Z

Reserved: 2025-12-29T14:34:16.005Z

Link: CVE-2026-21484

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-03T02:15:41.553

Modified: 2026-01-03T02:15:41.553

Link: CVE-2026-21484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses