CVE-2026-72917 PUBLISHED

AnythingLLM: Password recovery accepts one recovery code twice after whitespace normalization

Assigner: GitHub_M
Reserved: 10.08.2026 Published: 10.08.2026 Updated: 10.08.2026

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in server/utils/PasswordRecovery/index.js uses recoverAccount() to deduplicate the raw recoveryCodes values before trimming them, so one valid code submitted twice with different surrounding whitespace can satisfy the two-code check. Each normalized value can also match the same stored hash instead of consuming a distinct hash. An attacker who knows the target username and one recovery code can call POST /api/system/recover-account in multi-user mode, receive a password-reset token, and use POST /api/system/reset-password to take over the account, including an administrator account.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 5.9

Product Status

Vendor Mintplex-Labs
Product anything-llm
Versions
  • Version Affected versions >= 1.0.0, <= 1.15.0 is affected

References

Problem Types

  • CWE-180: Incorrect Behavior Order: Validate Before Canonicalize CWE
  • CWE-287: Improper Authentication CWE