CVE Feed

    Dashboard / CVE / CVE-2026-32717

    CVE-2026-32717

    AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, in multi-user mode, AnythingLLM blocks suspended users on the normal JWT-backed session path, but it does not block them on the browser extension API key path. If a user already has a valid brx-... browser extension API key, that key continues to work after suspension. As a result, a suspended user can still access browser extension endpoints, read reachable workspace metadata, and continue upload or embed operations even though normal authenticated requests are rejected.

    Published:Mar 13, 2026
    Last Modified:Mar 23, 2026
    EPS:Mar 13, 2026
    EPSS Score:0.00032
    CVSS Score:2.7

    Affected Products

    Vendor
    Mintplexlabs
    Product
    Anything-llm
    Vendor
    Mintplexlabs
    Product
    Anythingllm

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High