Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
AnythingLLM: Legacy mobile device tokens bypass multi-user workspace scoping after mode migration
Vulnerability Description
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, an approved mobile device token created in single-user mode can survive single-user -> multi-user migration even when the device record has userId = null. In multi-user mode, that stale token is still accepted by the mobile authentication middleware. Because no user is attached to the request, downstream mobile handlers fall back to unscoped data-access branches and return workspaces and workspace content without per-user filtering. This permits a pre-migration mobile token to enumerate a workspace assigned only to another user and retrieve victim-owned thread metadata and chat content in multi-user mode. This vulnerability is fixed in 1.13.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
AnythingLLM 安全漏洞
Vulnerability Description
AnythingLLM是Mintplex开源的一个一体化AI应用程序。 AnythingLLM 1.13.0之前版本存在安全漏洞,该漏洞源于单用户模式下创建的移动设备令牌在迁移到多用户模式后仍被接受,且未附加用户信息,导致下游移动处理程序回退到无范围数据访问分支,返回工作区和工作区内容而不进行每用户过滤,允许预迁移移动令牌枚举分配给其他用户的工作区并检索受害者拥有的线程元数据和聊天内容。
CVSS Information
N/A
Vulnerability Type
N/A