PT-2025-52256 · Unknown · Anything-Llm

·

CVE-2025-63390

·

Published

2025-12-18

·

Updated

2025-12-20

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions AnythingLLM version 1.8.5
Description An authentication bypass allows unauthenticated remote attackers to enumerate and retrieve detailed information about all configured workspaces. The issue is due to missing authentication checks in the /api/workspaces endpoint. Exposed data includes workspace identifiers (id, name, slug), AI model configurations (chatProvider, chatModel, agentProvider), system prompts (openAiPrompt), operational parameters (temperature, history length, similarity thresholds), vector search settings, chat modes, and timestamps.
Recommendations Apply authentication checks to the /api/workspaces endpoint to prevent unauthorized access to workspace configuration details.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-63390

Affected Products

Anything-Llm